mediumMultiple Choice
350-401 Practice Question: Given this configuration: aaa new-model aaa…
Given this configuration:
aaa new-model aaa authentication login default group radius aaa authorization exec default group radius aaa accounting exec default start-stop group radius
radius-server host 192.168.1.1 auth-port 1645 acct-port 1646 key radiuskey radius-server host 192.168.1.2 auth-port 1645 acct-port 1646 key radiuskey
Which statement is true about the RADIUS server ports?
⚠ Common exam trap
Cisco often tests the distinction between legacy (1645/1646) and standard (1812/1813) RADIUS ports, and the trap here is that candidates assume the default standard ports are always used, ignoring the explicit port configuration in the command.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The RADIUS authentication port is 1645 and accounting port is 1646.
The configuration explicitly sets the RADIUS authentication port to 1645 and the accounting port to 1646 using the `auth-port 1645` and `acct-port 1646` keywords in the `radius-server host` commands. These are the legacy RADIUS ports (as defined in RFC 2138/2139), which Cisco devices support by default when ports are not specified, but here they are explicitly configured.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The RADIUS authentication port is 1645 and accounting port is 1646.
Why this is correct
This answer is correct. The command's 'auth-port 1645' and 'acct-port 1646' keywords explicitly set the RADIUS authentication and accounting UDP ports, respectively. These non-default ports are commonly associated with legacy RADIUS implementations and are fully supported by Cisco IOS. By specifying these values, the device will send RADIUS packets to UDP 1645 for authentication and UDP 1646 for accounting, overriding the IANA defaults of 1812 and 1813.
- ✗
The RADIUS authentication port is 1812 and accounting port is 1813.
Why it's wrong here
This answer is incorrect because it describes the IANA default ports for RADIUS, but the command in question explicitly overrides those defaults. The presence of the 'auth-port 1645' and 'acct-port 1646' keywords means the device will not use 1812 and 1813 for this RADIUS server configuration. Without those keywords, 1812/1813 would be correct, but here the administrator has deliberately changed the ports.
- ✗
The RADIUS authentication port is 1646 and accounting port is 1645.
Why it's wrong here
This answer incorrectly reverses the two port assignments. In the given configuration, 'auth-port' is set to 1645, so authentication traffic must be sent to UDP port 1645. Accounting traffic is set to 1646 via the 'acct-port' keyword. Swapping these values would cause RADIUS Access-Request packets to arrive at the accounting port (1646) and Accounting-Request packets to arrive at the authentication port (1645), leading to silent failures and misrouted packets.
- ✗
The RADIUS ports are not configurable; this command will be rejected.
Why it's wrong here
This answer is wrong because Cisco IOS does allow RADIUS ports to be configured. The 'auth-port' and 'acct-port' keywords are valid under the 'radius server' configuration mode. The command will not be rejected; it is a standard way to define non-default RADIUS ports for a server. This flexibility supports legacy servers, test environments, or load balancing scenarios where custom port numbers are required.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
Learn chapter
SDN Controllers and Cisco ACI
Key term
RADIUS vs TACACS+
RADIUS and TACACS+ are two network protocols used to verify user identities and control access to network devices and services, with different approaches to security and flexibility.
Key term
AAA on Cisco Devices
AAA on Cisco devices is a security framework that controls who can access the network, what they can do, and keeps a record of their actions.
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.