Radius Function - Fujitsu PRIMERGY 10/40GbE Connection Blade 18/8+2 Function Manual

Table of Contents

Advertisement

2.26 RADIUS function

The RADIUS function is a function to manage AAA (Authentication, Authorization, Accounting) information by
using an external server (RADIUS server). When same AAA information is necessary in the multiple devices
and when a large amount of user information is to be managed, it is possible to manage by consolidating
authentication information and configuration information of user and connecting time of each user.
In this device, the RADIUS client function is supported.
The RADIUS client function is used by the following RADIUS support functions via AAA.
AAA information which can be used by each respective function is shown below.
RADIUS support
function
IEEE802.1X
Authentication
ARP authentication
DHCP MAC address
check
) It is an authentication which uses MAC address (HEX12 characters without separating character) for user
name and MAC address for password.
Backup configuration or load sharing configuration which uses multiple RADIUS servers is possiblefor the
RADIUS client function of this device.
The authentication server and the accounting server defined as RADIUS server have alive status and dead
status.
The meaning of each status is as follows.
▪ alive status
It is a status wherein the server is available.
It is used in preference of the higher (numerical value in the definition is small) priority server.
When multiple servers of the same priority exist, the server is selected randomly.
▪ dead status
It is the status where the server usage is temporarily stopped due to time out of request from
server address. Additionally, when the server of alive status exists, the value of the defined
priority is not used.
When time specified by the restoration stand by time is elapsed, it automatically is restored in
alive status.
If all servers are in dead status when authentication or accounting is carried out, take the trial
randomly at 1 server and the server wherefrom the response is obtained is restored in the alive
status.
Authentication Method
(authentication)
EAP-MD5 authentication, EAP-TLS
authentication
EAP-TTLS authentication, PEAP
authentication
PAP authentication / CHAP
authentication
()
PAP authentication / CHAP
authentication
()
User information
(authoraization)
Does not use
▪ Number of sending
and receiving octets
▪ Number of sending
and receiving packets
▪ Connection time
Does not use
Does not use
Does not use
Does not use
Accounting
(accouning)
Page 57 of 71

Advertisement

Table of Contents
loading

Table of Contents