Specifying The Radius Accounting Servers - H3C SR8800-F Configuration Manual

Comware 7 user access
Hide thumbs Also See for SR8800-F:
Table of Contents

Advertisement

When RADIUS server load sharing is enabled, the device distributes the workload over all servers
without considering the primary and secondary server roles. The device checks the weight value and
number of currently served users for each active server, and then determines the most appropriate
server in performance to receive an authentication request.
To specify RADIUS authentication servers for a RADIUS scheme:
Step
1.
Enter system view.
2.
Enter RADIUS scheme
view.
3.
Specify RADIUS
authentication servers.

Specifying the RADIUS accounting servers

You can specify one primary accounting server and a maximum of 16 secondary accounting servers
for a RADIUS scheme. Secondary servers provide AAA services when the primary server becomes
unavailable. The device searches for an active server in the order the secondary servers are
configured.
If redundancy is not required, specify only the primary server. A RADIUS accounting server can
function as the primary accounting server for one scheme and a secondary accounting server for
another scheme at the same time.
When RADIUS server load sharing is enabled, the device distributes the workload over all servers
without considering the primary and secondary server roles. The device checks the weight value and
number of currently served users for each active server, and then determines the most appropriate
server in performance to receive an accounting request.
RADIUS does not support accounting for FTP, SFTP, and SCP users.
To specify RADIUS accounting servers for a RADIUS scheme:
Step
1.
Enter system view.
2.
Enter RADIUS scheme view.
Command
system-view
radius scheme radius-scheme-name
Specify the primary RADIUS
authentication server:
primary authentication
{ ipv4-address | ipv6
ipv6-address } [ port-number |
key { cipher | simple } string |
test-profile profile-name |
vpn-instance
vpn-instance-name | weight
weight-value ] *
Specify a secondary RADIUS
authentication server:
secondary authentication
{ ipv4-address | ipv6
ipv6-address } [ port-number |
key { cipher | simple } string |
test-profile profile-name |
vpn-instance
vpn-instance-name | weight
weight-value ] *
Command
system-view
radius scheme radius-scheme-name
25
Remarks
N/A
N/A
By default, no authentication
servers are specified.
To support server status detection,
specify an existing test profile for
the RADIUS authentication server.
If the test profile does not exist, the
device cannot detect the server
status.
Two authentication servers in a
scheme, primary or secondary,
cannot have the same
combination of IP address, port
number, and VPN instance.
The weight weight-value option
takes effect only when the
RADIUS server load sharing
feature is enabled for the RADIUS
scheme.
Remarks
N/A
N/A

Advertisement

Table of Contents
loading

Table of Contents