Configuring A Radius Authorization Server; Optional) Setting A Shared Key For A Radius Server - Huawei Quidway S9300 Configuration Manual

Terabit routing switch
Table of Contents

Advertisement

Quidway S9300 Terabit Routing Switch
Configuration Guide - Security
The system view is displayed.
Step 2 Run:
radius-server template template-name
The RADIUS server template view is displayed.
Step 3 Run:
radius-server accounting ip-address port [ source loopback interface-number ]
The primary RADIUS accounting server is configured.
By default, the IP address of the primary RADIUS accounting server is 0.0.0.0 and the port
number is 0.
Step 4 (Optional) Run:
radius-server accounting ip-address port [ source loopback interface-number ]
secondary
The secondary RADIUS accounting server is configured.
By default, the IP address of the secondary RADIUS accounting server is 0.0.0.0 and the port
number is 0.
----End

1.4.5 Configuring a RADIUS Authorization Server

Context
The RADIUS authorization server is mainly used to dynamically authorize users during service
selection.
Procedure
Step 1 Run:
system-view
The system view is displayed.
Step 2 Run:
radius-server authorization ip-address { server-group group-name | shared-key
{ cipher | simple } key-string }
The RADIUS authorization server is configured.
By default, no RADIUS authorization server is configured in the S9300.
----End

1.4.6 (Optional) Setting a Shared Key for a RADIUS Server

Context
When exchanging authentication packets, the S9300 and the RADIUS server encrypt important
information such as the password by using the Message Digest 5 (MD5) algorithm to ensure the
Issue 06 (2010–01–08)
*
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
1 AAA and User Management Configuration
[ ack-reserved-interval interval ]
1-13

Advertisement

Table of Contents
loading

Table of Contents