HP A5830 Series Configuration Manual page 29

Security switch
Hide thumbs Also See for A5830 Series:
Table of Contents

Advertisement

authentication/authorization servers and accounting servers, or primary servers and secondary servers.
The parameters include the IP addresses of the servers, the shared keys, and the RADIUS server type.
RADIUS scheme configuration task list
Task
Creating a RADIUS scheme
Specifying the RADIUS authentication/authorization servers
Specifying the RADIUS accounting servers and the relevant parameters
Setting the shared keys for RADIUS packets
Setting the username format and traffic statistics units
Setting the supported RADIUS server type
Setting the maximum number of RADIUS request transmission attempts
Setting the status of RADIUS servers
Specifying the source IP address for outgoing RADIUS packets
Setting timers for controlling communication with RADIUS servers
Configuring RADIUS accounting-on
Configuring the IP address of the security policy server
Configuring interpretation of RADIUS class attribute as CAR parameters
Enabling the trap function for RADIUS
Enabling the RADIUS listening port of the RADIUS client
Displaying and maintaining RADIUS
Creating a RADIUS scheme
Before performing other RADIUS configurations, create a RADIUS scheme and enter RADIUS scheme
view:
To do...
1.
Enter system view.
2.
Create a RADIUS scheme and
enter RADIUS scheme view.
A RADIUS scheme can be referenced by multiple ISP domains at the same time.
Specifying the RADIUS authentication/authorization servers
You can specify one primary authentication/authorization server and up to 16 secondary
authentication/authorization servers for a RADIUS scheme so that the NAS can find a server for user
authentication/authorization when using the scheme. When the primary server is not available, a
secondary server is used, if there is one. In a scenario where redundancy is not required, specify only
the primary server.
In RADIUS, user authorization information is piggybacked in authentication responses sent to RADIUS
clients. It is neither allowed nor needed to specify a separate RADIUS authorization server.
To specify RADIUS authentication/authorization servers for a RADIUS scheme:
Use the command...
system-view
radius scheme radius-scheme-
name
21
Remarks
Required
Required
Optional
Optional
Optional
Optional
Optional
Optional
Optional
Optional
Optional
Optional
Optional
Optional
Optional
Optional
Remarks
Required
No RADIUS scheme by default

Advertisement

Table of Contents
loading

Table of Contents