HP 3600 v2 Series Command Reference Manual page 65

Hide thumbs Also See for 3600 v2 Series:
Table of Contents

Advertisement

port-number: Service port number of the primary authentication/authorization server, a UDP port
number in the range of 1 to 65535. The default is 1812.
key [ cipher | simple ] key: Specifies the shared key (case sensitive) for secure communication with the
primary RADIUS authentication/authorization server. Follow these guidelines:
This shared key must be the same as that configured on the RADIUS server.
With the cipher keyword specified, the key must be a ciphertext string of 12, 24, 32, 44, 64, 76, 88,
or 96 characters, for example, _(TT8F]Y\5SQ=^Q`MAF4<1!!, and the key will be displayed in
cipher text.
With the simple keyword specified, the key must be a plaintext string of 1 to 64 characters, for
example aabbcc, and the key will be displayed in plain text.
With neither the cipher keyword nor the simple keyword specified, the key must be a plaintext string
of 1 to 64 characters, and the key will be displayed in cipher text.
vpn-instance
authentication/authorization server belongs to, where vpn-instance-name is a case-sensitive string of 1 to
31 characters. If the server is on the public network, do not specify this option.
Description
Use the primary authentication command to specify the primary RADIUS authentication/authorization
server.
Use the undo primary authentication command to remove the configuration.
By default, no primary RADIUS authentication/authorization server is specified.
The IP addresses of the authentication/authorization servers and those of the accounting servers must be
of the same IP version.
The IP addresses of the primary and secondary authentication/authorization servers must be different
from each other. Otherwise, the configuration fails.
If the specified server resides on an MPLS L3VPN, specify the VPN by using the vpn-instance
vpn-instance-name option.
If you remove the primary authentication server when an authentication process is in progress, the
communication with the primary server will time out, and the switch will look for a server in active state
from the new primary server on.
NOTE:
The shared key configured by this command takes precedence over that configured by using the key
authentication [ cipher | simple ]
The VPN specified by this command takes precedence over the VPN specified for the RADIUS scheme.
Related commands: key and vpn-instance (RADIUS scheme view).
Examples
# For RADIUS scheme radius1, set the IP address of the primary authentication/authorization server to
10.1 10.1.1, the UDP port to 1812, and the shared key to the plaintext string hello, and specify to display
the key in cipher text.
<Sysname> system-view
[Sysname] radius scheme radius1
[Sysname-radius-radius1] primary authentication 10.110.1.1 1812 key hello
vpn-instance-name:
Specifies
the
MPLS
key
command.
55
L3VPN
that
the
primary
RADIUS

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents