Radius Scheme - HP 3600 v2 Series Command Reference Manual

Hide thumbs Also See for 3600 v2 Series:
Table of Contents

Advertisement

Default level
2: System level
Parameters
ipv4-address: IPv4 address in dotted decimal notation. It must be an address of the switch and cannot be
0.0.0.0, 255.255.255.255, a class D address, a class E address, or a loopback address.
ipv6 ipv6-address: Specifies an IPv6 address. It must be a unicast address of the switch that is neither a
loopback address nor a link-local address.
vpn-instance vpn-instance-name: Specifies the MPLS L3VPN that the source IPv4 address belongs to.
vpn-instance-name is a case-sensitive string of 1 to 31 characters. With a VPN specified, the command
specifies a private-network source IPv4 address. With no VPN specified, the command specifies a
public-network source IPv4 address.
Description
Use the radius nas-ip command to specify a source address for outgoing RADIUS packets.
Use the undo radius nas-ip command to remove the configuration.
By default, the source IP address of an outgoing RADIUS packet is the IP address of the outbound
interface.
You can specify up to one public-network source IP address and 15 private-network source IP addresses.
A newly specified public-network source IP address overwrites the previous one. Each VPN can have only
one private-network source IP address. A private-network source IP address newly specified for a VPN
overwrites the previous one.
The source IP address of RADIUS packets that a NAS sends must match the IP address of the NAS that
is configured on the RADIUS server. A RADIUS server identifies a NAS by its IP address. Upon receiving
a RADIUS packet, a RADIUS server checks whether the source IP address of the packet is the IP address
of any managed NAS. If yes, the server processes the packet. If not, the server drops the packet.
NOTE:
The setting configured by the nas-ip command in RADIUS scheme view is only for the RADIUS scheme,
whereas that configured by the radius nas-ip command in system view is for all RADIUS schemes. The
setting in RADIUS scheme view takes precedence.
Related commands: nas-ip.
Examples
# Set the IP address for the switch to use as the source address of the RADIUS packets to 129.10.10.1.
<Sysname> system-view
[Sysname] radius nas-ip 129.10.10.1

radius scheme

Syntax
radius scheme radius-scheme-name
undo radius scheme radius-scheme-name
View
System view
58

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents