HP MSR Series Configuration Manual page 48

Hpe flexnetwork msr router series
Hide thumbs Also See for MSR Series:
Table of Contents

Advertisement

Step
3.
Enable accounting-on.
Enabling the extended accounting-on feature
This feature enhances the accounting-on feature. It takes effect on a distributed device whose SPUs
are rebooted without the reboot of the whole device.
The extended accounting-on feature enables the device to automatically send an extended
accounting-on packet to the RADIUS server after an SPU reboot. Upon receiving the extended
accounting-on packet, the RADIUS server logs out all online users who access the device through
the SPU.
This feature requires the RADIUS server to run on IMC.
For the extended accounting-on feature to take effect, you must enable the accounting-on feature.
The extended accounting-on feature is applicable to IPoE, LAN, and PPP users. The feature is not
applicable to portal users, because all portal user information is saved on MPUs.
To enable the extended accounting-on feature for a RADIUS scheme:
Step
1.
Enter system view.
2.
Enter RADIUS scheme view.
3.
Enable extended
accounting-on.
Configuring the IP addresses of the security policy servers
The NAS verifies the validity of received control packets and accepts only control packets from
known servers. To use a security policy server that is independent of the AAA servers, configure the
IP address of the security policy server on the NAS.
The security policy server is the management and control center of the HPE EAD solution. To
implement all EAD functions, configure both the IP address of the security policy server and that of
the IMC Platform on the NAS.
To configure the IP address of a security policy server for a scheme:
Step
1.
Enter system view.
2.
Enter RADIUS scheme
view.
3.
Specify a security policy
server.
Interpreting the RADIUS class attribute as CAR parameters
A RADIUS server might deliver CAR parameters for user-based traffic monitoring and control by
using the RADIUS class attribute (attribute 25). You can configure the device to interpret the class
attribute to CAR parameters in the RADIUS packets to be forwarded to users.
To configure the device to interpret the RADIUS class attribute as CAR parameters:
Command
accounting-on enable [ interval
seconds | send send-times ] *
Command
system-view
radius scheme
radius-scheme-name
accounting-on extended
Command
system-view
radius scheme
radius-scheme-name
security-policy-server
{ ipv4-address | ipv6 ipv6-address }
[ vpn-instance
vpn-instance-name ]
33
Remarks
By default, the accounting-on
feature is disabled.
Remarks
N/A
N/A
By default, the extended
accounting-on feature is disabled.
Remarks
N/A
N/A
By default, no security policy server
is specified for a scheme.
You can specify a maximum of
eight security policy servers for a
RADIUS scheme.

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents