Radius Nas-Ip - Huawei Quidway S8500 Series Command Manual

Routing switches
Hide thumbs Also See for Quidway S8500 Series:
Table of Contents

Advertisement

Command Manual – Security
Quidway S8500 Series Routing Switches
Use the undo primary authentication command to restore the default IP address and
port number of the primary RADIUS authentication/authorization.
By default, the primary authentication server of the RADIUS scheme created by the
system, whose name is "system", uses IP address of 127.0.0.1 and UDP port of 1645.
The secondary authentication server uses IP address of 0.0.0.0 and UDP port of 1812.
The primary and secondary authentication server of a newly created RADIUS scheme
uses IP address of 0.0.0.0 and UDP port of 1812.
After creating a RADIUS scheme, you are supposed to set IP addresses and UDP port
numbers
authentication/authorization servers and accounting servers. In real networking
environments, the above parameters shall be set according to the specific
requirements. However, at least you have to set one authentication/authorization
server and an accounting server. Besides, ensure that the RADIUS service port
settings on the switch is consistent with the port settings on the RADIUS server.
Related command: key, radius scheme , state.
Example
# Set the IP address of the primary authentication/authorization server of RADIUS
scheme, "huawei", to 10.110.1.1 and the UDP port 1812 to provide RADIUS
authentication/authorization service.
[Quidway-radius-huawei] primary authentication auth 10.110.1.1 1812

2.2.14 radius nas-ip

Syntax
radius nas-ip ip-address [ vpn-instance vpn-instance-name ]
undo radius nas-ip [ vpn-instance vpn-instance-name ]
View
System view
Parameter
ip-address: Source IP address expressed in the format of dotted decimal notation. It
must be a legal unicast address.
vpn-instance-name: The name of VPN instances, which is a string ranging of 1 to 19
characters.
Description
Use the radius nas-ip command to configure the nas-ip of the global public network.
Only one public network nas-ip can be configured globally. Use the radius nas-ip
ip-address vpn-instance command to configure the nas-ip of the global private
for
the
RADIUS
Huawei Technologies Proprietary
2-35
Chapter 2 AAA and RADIUS/HWTACACS Protocol
servers,
including
Configuration Commands
primary/secondary

Advertisement

Table of Contents
loading

Table of Contents