Specifying A Security Policy Server - 3Com 4510G Configuration Manual

3com switch 4510g family
Table of Contents

Advertisement

To do...
Set the real-time accounting
interval
The maximum number of retransmission attempts of RADIUS packets multiplied by the RADIUS
server response timeout period cannot be greater than 75. This product is also the upper limit of
the timeout time of different access modules.
For an access module, the maximum number of retransmission attempts multiplied by the
RADIUS server response timeout period must be smaller than the timeout time. Otherwise,
stop-accounting messages cannot be buffered, and the primary/secondary server switchover
cannot take place. For example, as the timeout time of voice access is 10 seconds, the product of
the two parameters cannot exceed 10 seconds; as the timeout time of Telnet access is 30
seconds, the product of the two parameters cannot exceed 30 seconds. For detailed information
about timeout time of a specific access module, refer to the corresponding part in the Access
Volume.
To configure the maximum number of retransmission attempts of RADIUS packets, refer to the
command retry in the command manual.

Specifying a Security Policy Server

The core of the EAD solution is integration and cooperation, and the security policy server system is
the management and control center. As a collection of software, the security policy server system can
run on Windows and Linux to provide functions such as user management, security policy
management, security status assessment, security cooperation control, and security event audit.
This task allows you to configure the IP address of a security policy server. If the security policy server
and the RADIUS server reside on the same host, you can omit this task. When the device receives a
control packet from the security policy server, it checks whether the source IP address of the packet is
the IP address of the security policy server or RADIUS server. If not, the device considers the packet
invalid.
Follow these steps to specify a security policy server:
To do...
Enter system view
Create a RADIUS
scheme and enter its
view
Specify a security policy
server
Use the command...
timer realtime-accounting
minutes
Use the command...
system-view
radius scheme
radius-scheme-name
security-policy-server
ip-address
1-29
Remarks
Optional
12 minutes by default
Remarks
Required
By default, no RADIUS scheme is
present.
Optional
Not specified by default

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents