Huawei Quidway S6500 Series Operation Manual page 469

Hide thumbs Also See for Quidway S6500 Series:
Table of Contents

Advertisement

Operation Manual - Security
Quidway S6500 Series Ethernet Switches
"system" RADIUS scheme created by the system, the IP address of the primary
accounting server is 127.0.0.1, and the UDP port number is 1646.
In real networking environments, you can specify two RADIUS servers as the primary
and the secondary accounting servers respectively; or specify one server to function as
both.
To guarantee the normal interaction between NAS and RADIUS server, you are
supposed to guarantee the normal routes between RADIUS server and NAS before
setting IP address and UDP port of the RADIUS server. In addition, because RADIUS
protocol uses different UDP ports to receive/transmit authentication/authorization and
accounting packets, you shall set two different ports accordingly.
RFC2138/2139, authentication/authorization port number is 1812 and accounting port
number is 1813. However, you may use values other than the suggested ones.
(Especially for some earlier RADIUS Servers, authentication/authorization port number
is often set to 1645 and accounting port number is 1646.)
The RADIUS service port settings on Quidway Series Ethernet Switches are supposed
to be consistent with the port settings on RADIUS server. Normally, RADIUS
accounting service port is 1813.
II. Setting the Maximum Times of Real-time Accounting Request Failing to be
Responded
RADIUS server usually checks if a user is online with timeout timer. If the RADIUS
server has not received the real-time accounting packet from NAS for long, it will
consider that there is device failure and stop accounting. Accordingly, it is necessary to
disconnect the user at NAS end and on RADIUS server synchronously when some
unpredictable failure exists. Quidway Series Switches support to set maximum times of
real-time accounting request failing to be responded. NAS will disconnect the user if it
has not received real-time accounting response from RADIUS server for some
specified times.
You can use the following command to set the maximum times of real-time accounting
request failing to be responded
Perform the following configurations in RADIUS scheme view.
Table 2-19 Setting the maximum times of real-time accounting request failing to be
responded
Set maximum times of real-time accounting
request failing to be responded
Restore the maximum times to the default
value
Operation
Huawei Technologies Proprietary
2-16
Chapter 2 AAA and RADIUS Protocol
Command
retry
realtime-accounting
retry-times
undo retry realtime-accounting
Configuration
Suggested by

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Release 3000 series

Table of Contents