Configuring Radius Schemes - HPE Moonshot 45Gc Security Configuration Manual

Switch module
Table of Contents

Advertisement

Displaying and maintaining local users and local user groups
Execute display commands in any view.
Task
Display the local user
configuration and online user
statistics.
Display the user group
configuration.

Configuring RADIUS schemes

A RADIUS scheme specifies the RADIUS servers that the device can work with and defines a set of
parameters. The device uses the parameters to exchange information with the RADIUS servers,
including the server IP addresses, UDP port numbers, shared keys, and server types.
Configuration task list
Tasks at a glance
(Optional.)
(Required.)
(Required.)
(Optional.)
(Optional.)
(Optional.)
(Optional.)
(Optional.)
(Optional.)
(Optional.)
(Optional.)
(Optional.)
(Optional.)
(Optional.)
(Optional.)
(Optional.)
(Optional.)
Configuring a test profile for RADIUS server status detection
Use a test profile to detect whether a RADIUS authentication server is reachable at a detection
interval. To detect the RADIUS server status, you must configure the RADIUS server to use this test
profile in a RADIUS scheme.
With the test profile specified, the device sends a detection packet to the RADIUS server within each
detection interval. The detection packet is a simulated authentication request that includes the
specified user name in the test profile.
Command
display local-user [ class { manage | network } | idle-cut { disable |
enable } | service-type { ftp | http | https | lan-access | portal | ssh |
telnet | terminal } | state { active | block } | user-name user-name class
{ manage | network } | vlan vlan-id ]
display user-group [ group-name ]
Configuring a test profile for RADIUS server status detection
Creating a RADIUS scheme
Specifying the RADIUS authentication servers
Specifying the RADIUS accounting servers and the relevant parameters
Specifying the shared keys for secure RADIUS communication
Specifying an MPLS L3VPN instance for the scheme
Setting the username format and traffic statistics units
Setting the maximum number of RADIUS request transmission attempts
Setting the status of RADIUS servers
Enabling the RADIUS server load sharing feature
Specifying the source IP address for outgoing RADIUS packets
Setting RADIUS timers
Configuring the accounting-on feature
Configuring the IP addresses of the security policy servers
Configuring the Login-Service attribute check method for SSH, FTP, and terminal users
Enabling SNMP notifications for RADIUS
Displaying and maintaining RADIUS
22

Advertisement

Table of Contents
loading

Table of Contents