Download Print this page

Nas-Ip (Radius Scheme View) - HP FlexNetwork MSR Series Command Reference Manual

Comware 7 security
Hide thumbs Also See for FlexNetwork MSR Series:

Advertisement

Usage guidelines
The shared keys configured by using this command apply to all servers in the scheme. Make sure
the settings match the shared keys configured on the RADIUS servers.
The shared keys specified for specific RADIUS servers take precedence over the shared key
specified with this command.
Examples
# In RADIUS scheme radius1, set the shared key to ok in plaintext form for secure accounting
communication.
<Sysname> system-view
[Sysname] radius scheme radius1
[Sysname-radius-radius1] key accounting simple ok
Related commands
display radius scheme

nas-ip (RADIUS scheme view)

Use nas-ip to specify a source IP address for outgoing RADIUS packets.
Use undo nas-ip to delete the source IP address of the specified type for outgoing RADIUS packets.
Syntax
nas-ip { ipv4-address | ipv6 ipv6-address }
undo nas-ip [ ipv6 ]
Default
The source IP address of an outgoing RADIUS packet is that specified by using the radius nas-ip
command in system view.
If the radius nas-ip command is not configured, the source IP address is the IP address of the
outbound interface.
Views
RADIUS scheme view
Predefined user roles
network-admin
Parameters
ipv4-address: Specifies an IPv4 address, which must be an address of the device. The IP address
cannot be 0.0.0.0, 255.255.255.255, a class D address, a class E address, or a loopback address.
ipv6 ipv6-address: Specifies an IPv6 address, which must be a unicast address of the device and
cannot be a loopback address or a link-local address.
Usage guidelines
The source IP address of RADIUS packets that a NAS sends must match the IP address of the NAS
that is configured on the RADIUS server. A RADIUS server identifies a NAS by its IP address. Upon
receiving a RADIUS packet, a RADIUS server checks whether the source IP address of the packet is
the IP address of a managed NAS.
If the source IP address of the packet is the IP address of a managed NAS, the server
processes the packet.
If the source IP address of the packet is not the IP address of a managed NAS, the server drops
the packet.
92

Advertisement

loading