Setting The Shared Key For Radius Packets - 3Com MSR 50 Series Configuration Manual

3com msr 30-16: software guide
Hide thumbs Also See for MSR 50 Series:
Table of Contents

Advertisement

n
Setting the Shared Key
for RADIUS Packets
To do...
Configure the IP address and
UDP port of the secondary
RADIUS accounting server
Enable the device to buffer
stop-accounting requests
getting no responses
Set the maximum number of
stop-accounting request
transmission attempts
Set the maximum number of
accounting request
transmission attempts
In practice, you can specify two RADIUS servers as the primary and secondary
accounting servers respectively; or specify one server to function as both.
Besides, since RADIUS uses different UDP ports to receive
authentication/authorization and accounting packets, the port for
authentication/authorization must be different from that for accounting.
You can set the maximum number of stop-accounting request transmission
buffer, allowing the device to buffer and resend a stop-accounting request
until it receives a response or the number of transmission retries reaches the
configured limit. In the latter case, the device discards the packet.
You can set the maximum number of accounting request transmission
attempts on the device, allowing the device to disconnect a user when the
number of accounting request transmission attempts for the user reaches the
limit but it still receives no response to the accounting request.
The IP addresses of the primary and secondary accounting servers cannot be
the same. Otherwise, the configuration fails.
Currently, RADIUS does not support keeping accounts on FTP users.
The RADIUS client and RADIUS server use the MD5 algorithm to encrypt packets
exchanged between them and a shared key to verify the packets. Only when the
same key is used can they properly receive the packets and make responses.
Follow these steps to set the shared key for RADIUS packets:
To do...
Enter system view
Create a RADIUS scheme and
enter RADIUS scheme view
Set the shared key for RADIUS
authentication/authorization
or accounting packets
Use the command...
secondary accounting
ip-address [ port-number ]
stop-accounting-buffer
enable
retry stop-accounting
retry-times
retry realtime-accounting
retry-times
Use the command...
system-view
radius scheme
radius-scheme-name
key { accounting |
authentication } string
Configuring RADIUS
Remarks
Optional
The defaults are as follows:
0.0.0.0 for the IP address, and
1813 for the port.
Optional
Enabled by default
Optional
500 by default
Optional
5 by default
Remarks
-
Required
By default, no RADIUS scheme
is created.
Required
No key by default
1771

Hide quick links:

Advertisement

Table of Contents

Troubleshooting

loading

Table of Contents