HPE FlexNetwork 7500 Series Security Configuration Manual page 45

Table of Contents

Advertisement

Step
number of real-time
accounting attempts.
5.
(Optional.) Enable buffering
of RADIUS stop-accounting
requests to which no
responses have been
received.
6.
(Optional.) Set the maximum
number of transmission
attempts for individual
RADIUS stop-accounting
requests.
Specifying the shared keys for secure RADIUS communication
The RADIUS client and server use the MD5 algorithm and shared keys to generate the Authenticator
value for packet authentication and user password encryption. The client and server must use the
same key for each type of communication.
A key configured in this task is for all servers of the same type (accounting or authentication) in the
scheme. The key has a lower priority than a key configured individually for a RADIUS server.
To specify a shared key for secure RADIUS communication:
Step
1.
Enter system view.
2.
Enter RADIUS scheme
view.
3.
Specify a shared key for
secure RADIUS
communication.
Specifying an MPLS L3VPN instance for the scheme
The VPN instance specified for a RADIUS scheme applies to all authentication and accounting
servers in that scheme. If a VPN instance is also configured for an individual RADIUS server, the
VPN instance specified for the RADIUS scheme does not take effect on that server.
To specify a VPN instance for a scheme:
Step
1.
Enter system view.
2.
Enter RADIUS scheme view.
3.
Specify a VPN instance for the
RADIUS scheme.
Setting the username format and traffic statistics units
A username is in the userid@isp-name format, where the isp-name argument represents the user's
ISP domain name. By default, the ISP domain name is included in a username. However, older
Command
stop-accounting-buffer enable
retry stop-accounting retries
Command
system-view
radius scheme
radius-scheme-name
key { accounting |
authentication } { cipher | simple }
string
Command
system-view
radius scheme
radius-scheme-name
vpn-instance vpn-instance-name
31
Remarks
By default, the buffering
feature is enabled.
The default setting is 500.
Remarks
N/A
N/A
By default, no shared key is
specified for secure RADIUS
communication.
The shared key configured on the
device must be the same as the
shared key configured on the
RADIUS server.
Remarks
N/A
N/A
By default, a RADIUS
scheme belongs to the public
network.

Advertisement

Table of Contents
loading

Table of Contents