Configuring The Radius Dae Server Feature; Setting The Maximum Number Of Concurrent Login Users - HP FlexNetwork 10500 Series Security Configuration Manual

Hide thumbs Also See for FlexNetwork 10500 Series:
Table of Contents

Advertisement

Configuring the RADIUS DAE server feature

Dynamic Authorization Extensions (DAE) to RADIUS, defined in RFC 5176, can log off online users,
change their authorization information, or shut down their access interfaces. DAE uses the
client/server model.
In a RADIUS network, the RADIUS server typically acts as the DAE client and the NAS acts as the
DAE server.
When the RADIUS DAE server feature is enabled, the NAS performs the following operations:
1.
Listens to the default or specified UDP port to receive DAE requests.
2.
Logs off online users who match the criteria in the requests, changes their authorization
information, or shuts down their access interfaces.
3.
Sends DAE responses to the DAE client.
DAE defines the following types of packets:
Disconnect Messages (DMs)—The DAE client sends DM requests to the DAE server to log off
specific online users.
Change of Authorization Messages (CoA Messages)—The DAE client sends CoA requests
to the DAE server for the following purposes:
Change the authorization information of specific online users.
Shut down the access interfaces of users.
To configure the RADIUS DAE server feature:
Step
1.
Enter system view.
2.
Enable the RADIUS DAE
server feature and enter
RADIUS DAE server view.
3.
Specify a RADIUS DAE
client.
4.
Specify the RADIUS DAE
server port.
Setting the maximum number of concurrent login
users
Perform this task to set the maximum number of concurrent users who can log on to the device
through a specific protocol, regardless of their authentication methods. The authentication methods
include no authentication, local authentication, and remote authentication.
To set the maximum number of concurrent login users:
Step
1.
Enter system view.
Command
system-view
radius dynamic-author server
client { ip ipv4-address | ipv6
ipv6-address } [ key { cipher |
simple } string | vpn-instance
vpn-instance-name ] *
port port-number
Command
system-view
48
Remarks
N/A
By default, the RADIUS DAE
server feature is disabled.
By default, no RADIUS DAE clients
are specified.
By default, the RADIUS DAE
server port is 3799.
Remarks
N/A

Advertisement

Table of Contents
loading

Table of Contents