HP FlexNetwork 10500 Series Security Configuration Manual page 38

Hide thumbs Also See for FlexNetwork 10500 Series:
Table of Contents

Advertisement

The RADIUS server is manually set to the blocked state.
The RADIUS scheme is deleted.
To configure a test profile for RADIUS server status detection:
Step
5.
Enter system view.
6.
Configure a test profile for
detecting the status of
RADIUS authentication
servers.
Creating a RADIUS scheme
Create a RADIUS scheme before performing any other RADIUS configurations. You can configure
up to 16 RADIUS schemes. A RADIUS scheme can be referenced by multiple ISP domains.
To create a RADIUS scheme:
Step
1.
Enter system view.
2.
Create a RADIUS scheme
and enter RADIUS scheme
view.
Specifying the RADIUS authentication servers
A RADIUS authentication server completes authentication and authorization together, because
authorization information is piggybacked in authentication responses sent to RADIUS clients.
You can specify one primary authentication server and up to 16 secondary authentication servers for
a RADIUS scheme. Secondary servers provide AAA services when the primary server becomes
unavailable. The device searches for an active server in the order the secondary servers are
configured.
If redundancy is not required, specify only the primary server. A RADIUS authentication server can
act as the primary authentication server for one scheme and a secondary authentication server for
another scheme at the same time.
When RADIUS server load sharing is enabled, the device distributes the workload over all servers
without considering the primary and secondary server roles. The device checks the weight value and
number of currently served users for each active server, and then determines the most appropriate
server in performance to receive an authentication request.
To specify RADIUS authentication servers for a RADIUS scheme:
Step
1.
Enter system view.
2.
Enter RADIUS scheme
view.
Command
system-view
radius-server test-profile
profile-name username name
[ interval interval ]
Command
system-view
radius scheme
radius-scheme-name
Command
system-view
radius scheme radius-scheme-name
24
Remarks
N/A
By default, no test profiles exist.
You can configure multiple test
profiles in the system.
Remarks
N/A
By default, no RADIUS scheme is
defined.
Remarks
N/A
N/A

Advertisement

Table of Contents
loading

Table of Contents