HP 6600 Security Configuration Manual page 48

Table of Contents

Advertisement

Step
1.
Enter system view.
2.
Specify a source IP address
for outgoing RADIUS packets.
To specify a source IP address for a specific RADIUS scheme:
Step
1.
Enter system view.
2.
Enter RADIUS scheme view.
3.
Specify a source IP address
for outgoing RADIUS packets.
Specifying a backup source IP address for outgoing RADIUS packets
The following matrix shows the feature and router compatibility:
Feature
Specifying a backup source IP address for
outgoing RADIUS packets
In a stateful failover scenario, the active device authenticates portal users by interacting with the RADIUS
server, and synchronizes its online portal user information to the standby device through the backup link
established between them. The standby device only receives and processes synchronization messages
from the active device. However, if the active device fails, the RADIUS server cannot send RADIUS
packets to the standby device because it does not have the IP address of the standby device.
To prevent such problems, configure the source IP address for outgoing RADIUS packets on each device
as the backup source IP address for outgoing RADIUS packets on the other device. With this
configuration, the active device will send the source IP address for outgoing RADIUS packets configured
on the standby device to the RADIUS server, so that the RADIUS server can send unsolicited RADIUS
packets to the standby device.
You can specify a backup IP address for outgoing RADIUS packets in RADIUS scheme view for a specific
RADIUS scheme, or in system view for all RADIUS schemes whose servers are in a VPN or the public
network. Before sending a RADIUS packet, the NAS selects a backup source IP address in the following
order:
1.
The backup source IP address specified for the RADIUS scheme.
2.
The backup source IP address specified in system view for the VPN or public network, depending
on where the RADIUS server resides.
If no backup source IP address is specified in the views, the NAS sends no backup source IP address to
the server.
To specify a backup source IP address for all RADIUS schemes of a VPN or the public network:
Command
system-view
radius nas-ip { ip-address | ipv6
ipv6-address } [ vpn-instance
vpn-instance-name ]
Command
system-view
radius scheme
radius-scheme-name
nas-ip { ip-address | ipv6
ipv6-address }
6602
Yes
34
Remarks
N/A
By default, the IP address of the
outbound interface is used as the
source IP address.
Remarks
N/A
N/A
By default, the IP address of the
outbound interface is used as the
source IP address.
HSR6602
6604/6608/6616
No
No

Advertisement

Table of Contents
loading

This manual is also suitable for:

Hsr6600

Table of Contents