HPE FlexNetwork 7500 Series Security Configuration Manual page 51

Table of Contents

Advertisement

Step
3.
Enable accounting-on.
4.
(Optional.) Enable extended
accounting-on.
Interpreting the RADIUS class attribute as CAR parameters
A RADIUS server may deliver CAR parameters for user-based traffic monitoring and control by using
the RADIUS class attribute (attribute 25) in RADIUS packets. You can configure the device to
interpret the class attribute to CAR parameters.
To configure the device to interpret the RADIUS class attribute as CAR parameters:
Step
1.
Enter system view.
2.
Enter RADIUS scheme view.
3.
Interpret the RADIUS class
attribute as CAR parameters.
Configuring the Login-Service attribute check method for SSH, FTP, and terminal users
The device supports the following check methods for the Login-Service attribute (RADIUS attribute
15) of SSH, FTP, and terminal users:
Strict—Matches Login-Service attribute values 50, 51, and 52 for SSH, FTP, and terminal
services, respectively.
Loose—Matches the standard Login-Service attribute value 0 for SSH, FTP, and terminal
services.
An Access-Accept packet received for a user must contain the matching attribute value. Otherwise,
the user cannot log in to the device.
Use the loose check method only when the server does not issue Login-Service attribute values 50,
51, and 52 for SSH, FTP, and terminal users.
To configure the Login-Service attribute check method for SSH, FTP, and terminal users:
Step
1.
Enter system view.
2.
Enter RADIUS scheme view.
3.
Configure the Login-Service
attribute check method for
SSH, FTP, and terminal
users.
Configuring the MAC address format for RADIUS attribute 31
RADIUS servers of different types might have different requirements for the MAC address format in
RADIUS attribute 31. Configure the MAC address format for RADIUS attribute 31 to meet the
requirements of the RADIUS servers.
To configure the MAC address format for RADIUS attribute 31:
Command
accounting-on enable [ interval
interval | send send-times ] *
accounting-on extended
Command
system-view
radius scheme
radius-scheme-name
attribute 25 car
Command
system-view
radius scheme
radius-scheme-name
attribute 15 check-mode { loose |
strict }
37
Remarks
By default, the accounting-on
feature is disabled.
By default, extended
accounting-on is disabled.
Remarks
N/A
N/A
By default, the RADIUS class
attribute is not interpreted as
CAR parameters.
Remarks
N/A
N/A
The default check method is
strict.

Advertisement

Table of Contents
loading

Table of Contents