The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Managing devices access using RADIUS

Prev Next

Remote Authentication Dial In User Service (RADIUS) is an AAA (authentication, authorization, and accounting) protocol for applications such as network access.

While connecting to the Sensor CLI through the client program, you are required to enter a user name and password. The information is passed through a Network Access Device (NAD) device, and then to a RADIUS server over the RADIUS protocol. The RADIUS server checks if the information is correct using authentication scheme like PAP. If accepted, the server authorizes the access.

Using the Manager, you can configure a RADIUS server to authenticate users. You can configure a maximum of two RADIUS servers. If the first RADIUS server is not available for communication, due to a network failure, the client program tries to communicate with the second server. If authentication fails at any available servers, the client program does not communicate with the other available servers.

The RADIUS action enables you to use RADIUS to authenticate existing users on their RADIUS server. Only the PAP (MD5) algorithm is supported for RADIUS user password.

Note

Trellix recommends that either RADIUS users or local users on the Sensor should be configured. If both are required, ensure that users with the same name are not present in the Sensor and the RADIUS server.

Consider the following when configuring a RADIUS server:

  • The RADIUS service has to be started for it to communicate with its clients.

  • The Sensor IP address has to be configured in the RADIUS server.

  • Users have to be added to the RADIUS server.

  • When users or settings are changed in the files of the RADIUS server, the current service has to be stopped and started for the changes to take effect.

You can configure the RADIUS authentication for the admin domain from Devices → <Admin Domain Name> → Global → Common Device Settings → Remote Access → RADIUS. You can configure RADIUS authentication at the Sensor under Devices → <Admin Domain Name> → Devices → <Device Name> → Setup → Remote Access → RADIUS.

GUID-D37B399F-9935-44E0-9190-CE04094B5393-low.png