Configuring Vpn Of Radius Server; Setting The Maximum Retry Times For Radius Request Packets - H3C S9500 Series Operation Manual

Routing switches
Hide thumbs Also See for S9500 Series:
Table of Contents

Advertisement

Operation Manual – Security
H3C S9500 Series Routing Switches
Table 2-13 Set RADIUS packet encryption key
Set RADIUS authentication/authorization packet
encryption key
Restore
authentication/authorization packet encryption key
Set RADIUS accounting packet encryption key
Restore the default RADIUS accounting packet
encryption key
By default, the encryption keys of RADIUS authentication/authorization and accounting
packets are null.

2.3.4 Configuring VPN of RADIUS Server

The default address of the RADIUS Server is the address of the public network. If the
RADIUS Server is built under a private network, you must specify the VPN to which the
RADIUS Server belongs when configuring the RADIUS Server.
Use the following commands to configure the VPN of the RADIUS Server.
Perform the following configuration in RADIUS scheme view.
Table 2-14 Configure the VPN of the RADIUS Server
Set the VPN that the RADIUS Server belongs to
Restore the VPN attribute of RADIUS Server to the
default value
The RADIUS Server does not belong to any VPN by default.

2.3.5 Setting the Maximum Retry Times for RADIUS Request Packets

Because RADIUS Protocol carries data through UDP packets, its communication
process is not reliable. If the RADIUS Server does not respond to the NAS within the
time specified by the response timeout timer, it is necessary for the NAS to retry
sending the RADIUS request packets to the RADIUS Server. If the number of retry
times exceeds maximum retry times while the RADIUS Server still does not respond,
the NAS will assume its communication with the current RADIUS Server to have been
cut off and will send request packets to another RADIUS Server.
Use the following commands to set the maximum retry times of sending RADIUS
request packets.
Operation
the
default
Operation
2-18
Chapter 2 AAA and RADIUS/HWTACACS
Command
key authentication string
RADIUS
undo key authentication
key accounting string
undo key accounting
Command
vpn-instance vpn-name
undo vpn-instance
Protocol Configuration

Advertisement

Table of Contents
loading

This manual is also suitable for:

S9505S9508S9512

Table of Contents