Configuring Shared Keys For Radius Messages - 3Com E4500-24 Cli Configuration Manual

Hp e4500-24: user guide
Table of Contents

Advertisement

Enable stop-accounting
request buffering
Set the maximum
number of transmission
attempts of a buffered
stop-accounting request.
Set the maximum
allowed number of
continuous real-time
accounting failures
In an actual network environment, you can specify one server as both the primary and secondary
accounting servers, as well as specifying two RADIUS servers as the primary and secondary
accounting servers respectively. In addition, because RADIUS adopts different UDP ports to
exchange authentication/authorization messages and accounting messages, you must set a port
number for accounting different from that set for authentication/authorization.
With stop-accounting request buffering enabled, the switch first buffers the stop-accounting
request that gets no response from the RADIUS accounting server, and then retransmits the
request to the RADIUS accounting server until it gets a response, or the maximum number of
transmission attempts is reached (in this case, it discards the request).
You can set the maximum allowed number of continuous real-time accounting failures. If the
number of continuously failed real-time accounting requests to the RADIUS server reaches the set
maximum number, the switch cuts down the user connection.
The IP address and port number of the primary accounting server of the default RADIUS scheme
"system" are 127.0.0.1 and 1646 respectively.
Currently, RADIUS does not support the accounting of FTP users.

Configuring Shared Keys for RADIUS Messages

Both RADIUS client and server adopt MD5 algorithm to encrypt RADIUS messages before they are
exchanged between the two parties. The two parties verify the validity of the RADIUS messages
received from each other by using the shared keys that have been set on them, and can accept and
respond to the messages only when both parties have the same shared key.
Follow these steps to configure shared keys for RADIUS messages:
To do...
Enter system view
Create a RADIUS scheme and
enter its view
stop-accounting-buffer
enable
retry stop-accounting
retry-times
retry realtime-accounting
retry-times
Use the command...
system-view
radius scheme
radius-scheme-name
2-13
Optional
By default, stop-accounting request
buffering is enabled.
Optional
By default, the system tries at most 500
times to transmit a buffered
stop-accounting request.
Optional
By default, the maximum allowed
number of continuous real-time
accounting failures is five. If five
continuous failures occur, the switch
cuts down the user connection.
Remarks
Required
By default, a RADIUS scheme
named "system" has already
been created in the system.

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

4500

Table of Contents