The appliance can validate username/password or token-based credentials against a RADIUS database. The below image shows typical RADIUS configuration options:
RADIUS authentication configuration options
You must modify your firewall or router to allow the appliance to communicate with your RADIUS server. The RADIUS authentication protocol typically uses port 1645/udp. In addition, you must configure your RADIUS server to include the IP address of the appliance as a RADIUS client (most often referred to as a Network Access Server).
Affinity servers should be used only for authentication servers that do not include full group search capabilities, such as RADIUS, RSA, and PKI servers.