HP 5120 SI Series Security Configuration Manual page 39

Hide thumbs Also See for 5120 SI Series:
Table of Contents

Advertisement

You can specify a source IP address for outgoing RADIUS packets in RADIUS scheme view for a specific
RADIUS scheme, or in system view for all RADIUS schemes. Before sending a RADIUS packet, a NAS
selects a source IP address in this order:
1.
The source IP address specified for the RADIUS scheme.
2.
The source IP address specified in system view.
3.
The IP address of the outbound interface specified by the route.
Follow these steps to specify a source IP address for all RADIUS schemes:
To do...
Enter system view
Specify a source IP address for
outgoing RADIUS packets
Follow these steps to specify a source IP address for a specific RADIUS scheme:
To do...
Enter system view
Enter RADIUS scheme view
Specify a source IP address for
outgoing RADIUS packets
Setting timers for controlling communication with RADIUS servers
The device uses the following types of timers to control the communication with a RADIUS server:
Server response timeout timer—Defines the RADIUS request retransmission interval. After sending
a RADIUS request (authentication/authorization or accounting request), the device starts this timer.
If the device receives no response from the RADIUS server before this timer expires, it resends the
request.
Server quiet timer—Defines the duration to keep an unreachable server in the blocked state. If a
server is not reachable, the device changes the server's status to blocked, starts this timer for the
server, and tries to communicate with another server in the active state. After this timer expires, the
device changes the status of the server back to active.
Real-time accounting timer—Defines the interval at which the device sends real-time accounting
packets to the RADIUS accounting server for online users. To implement real-time accounting, the
device must periodically send real-time accounting packets to the accounting server for online
users.
Follow these steps to set timers for controlling communication with RADIUS servers:
To do...
Enter system view
Enter RADIUS scheme view
Use the command...
system-view
radius nas-ip { ip-address |
ipv6 ipv6-address }
Use the command...
system-view
radius scheme
radius-scheme-name
nas-ip { ip-address | ipv6
ipv6-address }
Use the command...
system-view
radius scheme
radius-scheme-name
27
Remarks
Required
By default, the IP address of the outbound
interface is used as the source IP address.
Remarks
Required
By default, the IP address of the outbound
interface is used as the source IP address.
Remarks

Advertisement

Table of Contents
loading

Table of Contents