H3C S3100 Series Command Manual page 449

Hide thumbs Also See for S3100 Series:
Table of Contents

Advertisement

Examples
# Enable UDP ports for local RADIUS services.
<Sysname> system-view
System View: return to User View with Ctrl+Z.
[Sysname] local-server enable
local-server nas-ip
Syntax
local-server nas-ip ip-address key password
undo local-server nas-ip ip-address
View
System view
Parameters
nas-ip ip-address: Specifies the IP address of a network access server (NAS) that can use the local
RADIUS services. Here, ip-address is in dotted decimal notation.
key password: Sets the shared key between the local RADIUS server and the NAS. Here, password is
a string of up to 16 characters.
Description
Use the local-server nas-ip command to set the related parameters of the local RADIUS server.
Use the undo local-server nas-ip command to cancel a specified NAS setting for the local RADIUS
server.
By default, the local RADIUS server is enabled and it allows the access of NAS 127.0.0.1. That is, the
local device serves as both a RADIUS server and a network access server, and all authentications are
performed locally. The default share key is null.
Note that:
The message encryption key set by the local-server nas-ip ip-address key password command
must be identical with the authentication/authorization message encryption key set by the key
authentication command in the RADIUS scheme view of the RADIUS scheme on the specified
NAS that uses this switch as its authentication server.
The switch supports the IP addresses and shared keys of at most 16 network access servers
(including the local device); that is, when the switch serves as a RADIUS server, it can provide
authentication service to at most 16 NASs simultaneously.
When serving as a local RADIUS server, the switch does not support EAP authentication (that is
you
cannot
authentication-method eap command).
Related commands: radius scheme, state, local-server enable.
Examples
# Allow the local RADIUS server to provide services to NAS 10.110.1.2 with shared key aabbcc.
<Sysname> system-view
System View: return to User View with Ctrl+Z.
set
the
802.1x
authentication
method
as
1-45
by
using
the
eap
dot1x

Advertisement

Table of Contents
loading

Table of Contents