HP VSR1000 Security Configuration Manual page 41

Virtual services router
Table of Contents

Advertisement

A short real-time accounting interval helps improve accounting precision but requires many system
resources. When there are 1000 or more users, set the interval to 15 minutes or longer.
To set RADIUS timers:
Step
1.
Enter system view.
2.
Enter RADIUS scheme view.
3.
Set the RADIUS server
response timeout timer.
4.
Set the quiet timer for the
servers.
5.
Set the real-time accounting
timer.
Configuring the accounting-on feature
When the accounting-on feature is enabled, the device automatically sends an accounting-on packet to
the RADIUS server after a reboot. Upon receiving the accounting-on packet, the RADIUS server logs out
all online users so they can log in again through the device. Without this feature, users cannot log in
again after the reboot, because the RADIUS server considers them to come online.
You can configure the interval for which the device waits to resend the accounting-on packet and the
maximum number of retries.
To configure the accounting-on feature for a RADIUS scheme:
Step
1.
Enter system view.
2.
Enter RADIUS scheme view.
3.
Enable accounting-on.
Configuring the IP addresses of the security policy servers
The NAS verifies the validity of received control packets and accepts only control packets from known
servers. To use a security policy server that is independent of the AAA servers, configure the IP address
of the security policy server on the NAS.
The security policy server is the management and control center of the HP EAD solution. To implement all
EAD functions, configure both the IP address of the security policy server and that of the IMC Platform on
the NAS.
To configure the IP address of a security policy server for a scheme:
Step
1.
Enter system view.
2.
Enter RADIUS scheme
view.
Command
system-view
radius scheme
radius-scheme-name
timer response-timeout seconds
timer quiet minutes
timer realtime-accounting minutes
Command
system-view
radius scheme
radius-scheme-name
accounting-on enable [ interval
seconds | send send-times ] *
Command
system-view
radius scheme radius-scheme-name
31
Remarks
N/A
N/A
The default setting is 3 seconds.
The default setting is 5 minutes.
The default setting is 12 minutes.
Remarks
N/A
N/A
By default, the accounting-on
feature is disabled.
Remarks
N/A
N/A

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents