HP 6125G Configuration Manual page 38

Security configuration guide
Hide thumbs Also See for 6125G:
Table of Contents

Advertisement

Step
2.
Enter RADIUS scheme view.
3.
Set the RADIUS server
response timeout timer.
4.
Set the quiet timer for the
servers.
5.
Set the real-time accounting
timer.
For a type of users, the maximum number of transmission attempts multiplied by the RADIUS server
response timeout period must be less than the client connection timeout time and must not exceed
75 seconds. Otherwise, stop-accounting messages cannot be buffered, and the
primary/secondary server switchover cannot take place. For example, the product of the two
parameters must be less than 10 seconds for voice users, and less than 30 seconds for Telnet users
because the client connection timeout period for voice users is 10 seconds and that for Telnet users
is 30 seconds.
When you configure the maximum number of RADIUS packet transmission attempts and the
RADIUS server response timeout period, be sure to take the number of secondary servers into
account. If the retransmission process takes too much time, the client connection in the access
module may be timed out while the switch is trying to find an available server.
When a number of secondary servers are configured, the client connections of access modules that
have a short client connection timeout period may still be timed out during initial authentication or
accounting, even if the packet transmission attempt limit and server response timeout period are
configured with small values. In this case, the next authentication or accounting attempt may
succeed because the switch has set the state of the unreachable servers to blocked and the time for
finding a reachable server is shortened.
Be sure to set the server quiet timer properly. Too short a quiet timer may result in frequent
authentication or accounting failures because the switch has to repeatedly attempt to communicate
with an unreachable server that is in active state.
For more information about the maximum number of RADIUS packet transmission attempts, see
"Setting the maximum number of RADIUS request transmission
Configuring RADIUS accounting-on
The accounting-on feature enables a switch to send accounting-on packets to the RADIUS server after it
reboots, making the server log out users who logged in through the switch before the reboot. Without this
feature, users who were online before the reboot cannot re-log in after the reboot, because the RADIUS
server considers they are already online.
If a switch sends an accounting-on packet to the RADIUS server but receives no response, it resends the
packet to the server at a particular interval for a specified number of times.
To configure the accounting-on feature for a RADIUS scheme:
Command
radius scheme
radius-scheme-name
timer response-timeout seconds
timer quiet minutes
timer realtime-accounting minutes
28
Remarks
N/A
Optional.
The default RADIUS server
response timeout timer is 3
seconds.
Optional.
The quiet timer is 5 minutes.
Optional.
The default real-time accounting
timer is 12 minutes.
attempts."

Advertisement

Table of Contents
loading

This manual is also suitable for:

6125 blade switch series

Table of Contents