Configuring Radius Schemes - HP MSR2000 Configuration Manual

Hide thumbs Also See for MSR2000:
Table of Contents

Advertisement

Configuring RADIUS schemes

A RADIUS scheme specifies the RADIUS servers that the device can work with and defines a set of
parameters that the device uses to exchange information with the RADIUS servers, including the IP
addresses of the servers, UDP port numbers, shared keys, and server types.
Configuration task list
Tasks at a glance
(Required.)
(Required.)
(Optional.)
(Optional.)
(Optional.)
(Optional.)
(Optional.)
(Optional.)
(Optional.)
(Optional.)
(Optional.)
(Optional.)
(Optional.)
Creating a RADIUS scheme
Create a RADIUS scheme before performing any other RADIUS configurations. You can configure up to
16 RADIUS schemes. A RADIUS scheme can be referenced by multiple ISP domains.
To create a RADIUS scheme:
Step
1.
Enter system view.
2.
Create a RADIUS scheme and
enter its view.
Specifying the RADIUS authentication servers
A RADIUS authentication server completes authentication and authorization together, because
authorization information is piggybacked in authentication responses sent to RADIUS clients.
You can specify one primary authentication server and up to 16 secondary authentication servers for a
RADIUS scheme. When the primary server is not available, the device tries to communicate with the
secondary servers in the order they are configured, and communicates with the first secondary server in
active state. If redundancy is not required, specify only the primary server. A RADIUS authentication
server can function as the primary authentication server for one scheme and a secondary authentication
server for another scheme at the same time.
To specify RADIUS authentication servers for a RADIUS scheme:
Creating a RADIUS scheme
Specifying the RADIUS authentication servers
Specifying the RADIUS accounting servers and the relevant parameters
Specifying the shared keys for secure RADIUS communication
Specifying a VPN for the scheme
Setting the username format and traffic statistics units
Setting the maximum number of RADIUS request transmission attempts
Setting the status of RADIUS servers
Specifying the source IP address for outgoing RADIUS packets
Setting RADIUS timers
Configuring the accounting-on feature
Configuring the IP addresses of the security policy servers
Displaying and maintaining RADIUS
Command
system-view
radius scheme
radius-scheme-name
21
Remarks
N/A
By default, no RADIUS scheme is
defined.

Advertisement

Table of Contents
loading

This manual is also suitable for:

Msr3000Msr4000

Table of Contents