Configuring User Re-Authentication At Reboot; Configuration Example For User Re-Authentication At Reboot; Setting The Radius Packet Encryption Key - 3Com 5500-SI Configuration Manual

5500 series
Hide thumbs Also See for 5500-SI:
Table of Contents

Advertisement

Configuring User
Re-authentication at
Reboot
Configuration Example
for User
Re-authentication at
Reboot
Setting the RADIUS
Packet Encryption Key
The switch can automatically generate the main attributes (NAS-ID, NAS-IP and
session ID) of the Accounting-On packets. However, you can also manually configure
the NAS-IP attribute with the nas-ip command. When doing this, be sure to
configure a correct and valid IP address. If this attribute is not manually configured,
the switch will automatically select the IP address of the VLAN interface as the NAS-IP
address.
Table 457 Configure user re-authentication at reboot
Operation
Enter system view
Enter RADIUS scheme view
Enable user re-authentication
at reboot
Network requirements
Enable user re-authentication at reboot.
Configuration procedure
1 Enter system view.
<S5500> system-view
2 Enter the view of the RADIUS scheme named CAMS (supposing this scheme has
already existed).
[S5500] radius scheme CAMS
3 Enable user re-authentication at reboot.
[S5500-radius-CAMS] accounting-on enable
The RADIUS client (Switch system) and the RADIUS server use MD5 algorithm to
encrypt the exchanged packets. The two ends verify the packet through setting the
encryption key. Only when the keys are identical can both ends accept the packets
from each other and give responses.
You can use the following commands to set the encryption key for RADIUS packets.
Perform the following configurations in RADIUS Scheme View.
Table 458 Setting the RADIUS Packet Encryption Key
Operation
Set RADIUS authentication/authorization packet
encryption key
Restore the default RADIUS
authentication/authorization packet encryption key.
Set RADIUS accounting packet key
Restore the default RADIUS accounting packet key
User Re-authentication at Reboot 425
Command
system-view
radius scheme
radius-scheme-name
accounting-on enable [
send times | interval
interval ]
Command
key authentication string
undo key authentication
key accounting string
undo key accounting
Description
Optional
By default, this feature is disabled.
When this feature is enabled, the
system can send the Accounting-On
packet at most 15 times at intervals
of three seconds by default.

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

5500-ei5500g-ei

Table of Contents