Configuring The Radius Dae Server Feature; Setting The Maximum Number Of Concurrent Login Users - HPE Moonshot 45Gc Security Configuration Manual

Switch module
Table of Contents

Advertisement

Step
1.
Enter system view.
2.
Enable the session-control
feature.

Configuring the RADIUS DAE server feature

Dynamic Authorization Extensions (DAE) to RADIUS, defined in RFC 5176, can log off online users
or change their authorization information. DAE uses the client/server model.
In a RADIUS network, the RADIUS server typically acts as the DAE client and the NAS acts as the
DAE server.
When the RADIUS DAE server feature is enabled, the NAS performs the following operations:
1.
Listens to the default or specified UDP port to receive DAE requests.
2.
Logs off online users who match the criteria in the requests, or changes their authorization
information.
3.
Sends DAE responses to the DAE client.
DAE defines the following types of packets:
Disconnect Messages (DMs)—The DAE client sends DM requests to the DAE server to log off
specific online users.
Change of Authorization Messages (CoA Messages)—The DAE client sends CoA requests
to the DAE server to change the authorization information of specific online users.
To configure the RADIUS DAE server feature:
Step
1.
Enter system view.
2.
Enable the RADIUS DAE
server feature and enter
RADIUS DAE server view.
3.
Specify a RADIUS DAE
client.
4.
Specify the RADIUS DAE
server port.
Setting the maximum number of concurrent login
users
Perform this task to set the maximum number of concurrent users who can log on to the device
through a specific protocol, regardless of their authentication methods. The authentication methods
include no authentication, local authentication, and remote authentication.
To set the maximum number of concurrent login users:
Command
system-view
radius session-control enable
Command
system-view
radius dynamic-author server
client { ip ipv4-address | ipv6
ipv6-address } [ key { cipher |
simple } string | vpn-instance
vpn-instance-name ] *
port port-number
48
Remarks
N/A
By default, the session-control
feature is disabled.
Remarks
N/A
By default, the RADIUS DAE
server feature is disabled.
By default, no RADIUS DAE clients
are specified.
By default, the RADIUS DAE
server port is 3799.

Advertisement

Table of Contents
loading

Table of Contents