Specifying A Security Policy Server - HP 4800G Series Configuration Manual

24/48 port
Table of Contents

Advertisement

To do...
Set the real-time accounting
interval
The maximum number of retransmission attempts of RADIUS packets multiplied by the RADIUS
server response timeout period cannot be greater than 75. This product is also the upper limit of the
timeout time of different access modules.
For an access module, the maximum number of retransmission attempts multiplied by the RADIUS
server response timeout period must be smaller than the timeout time. Otherwise, stop-accounting
messages cannot be buffered, and the primary/secondary server switchover cannot take place.
For example, as the timeout time of voice access is 10 seconds, the product of the two parameters
cannot exceed 10 seconds; as the timeout time of Telnet access is 30 seconds, the product of the
two parameters cannot exceed 30 seconds. For detailed information about timeout time of a
specific access module, refer to the corresponding part in the Access Volume.
To configure the maximum number of retransmission attempts of RADIUS packets, refer to the
command retry in the command manual.

Specifying a Security Policy Server

The core of the EAD solution is integration and cooperation, and the security policy server system is the
management and control center. As a collection of software, the security policy server system can run
on Windows and Linux to provide functions such as user management, security policy management,
security status assessment, security cooperation control, and security event audit.
This task allows you to configure the IP address of a security policy server. If the security policy server
and the RADIUS server reside on the same host, you can omit this task. When the device receives a
control packet from the security policy server, it checks whether the source IP address of the packet is
the IP address of the security policy server or RADIUS server. If not, the device considers the packet
invalid.
Follow these steps to specify a security policy server:
To do...
Enter system view
Create a RADIUS
scheme and enter its
view
Specify a security policy
server
Use the command...
timer realtime-accounting
minutes
Use the command...
system-view
radius scheme
radius-scheme-name
security-policy-server
ip-address
1-29
Remarks
Optional
12 minutes by default
Remarks
Required
By default, no RADIUS scheme is
present.
Optional
Not specified by default

Advertisement

Chapters

Table of Contents
loading

Table of Contents