3Com Switch 4800G 24-Port Configuration Manual page 769

Switch 4800g family 24-port, pwr 24-port, 48-port, pwr 48-port, 24-port sfp
Hide thumbs Also See for Switch 4800G 24-Port:
Table of Contents

Advertisement

n
Configuring Attributes
Related to the Data Sent
to the RADIUS Server
n
To do...
Set the status of the primary
RADIUS
authentication/authorization
server
Set the status of the primary
RADIUS accounting server
Set the status of the
secondary RADIUS
authentication/authorization
server
Set the status of the
secondary RADIUS accounting
server
If both the primary server and the secondary server are in the blocked state, it
is necessary to manually turn the secondary server to the active state so that
the secondary server can perform authentication. If the secondary server is still
in the blocked state, the primary/secondary switchover cannot take place.
If one server is in the active state while the other is blocked, the
primary/secondary switchover will not take place even if the active server is not
reachable.
Follow these steps to configure the attributes related to the data sent to the
RADIUS server:
To do...
Enter system view
Enable the RADIUS trap
function
Create a RADIUS scheme and
enter RADIUS scheme view
Specify the format of the
username to be sent to a
RADIUS server
Specify the unit for data flows
or packets to be sent to a
RADIUS server
Set the source
In RADIUS
IP address of
scheme view
the device to
In system view quit
send RADIUS
packets
Some earlier RADIUS servers cannot recognize usernames that contain an ISP
domain name, therefore before sending a username including a domain name
to such a RADIUS server, the device must remove the domain name. This
Use the command...
state primary
authentication { active |
block }
state primary accounting
{ active | block }
state secondary
authentication { active |
block }
state secondary accounting
{ active | block }
Use the command...
system-view
radius trap
{ accounting-server-down |
authentication-server-dow
n }
radius scheme
radius-scheme-name
user-name-format
{ with-domain |
without-domain }
data-flow-format { data
{ byte | giga-byte |
kilo-byte | mega-byte } |
packet { giga-packet |
kilo-packet | mega-packet |
one-packet } }*
nas-ip ip-address
radius nas-ip ip-address
Configuring RADIUS
769
Remarks
Optional
active for every server
configured with IP address in
the RADIUS scheme
Remarks
-
Optional
Disabled by default
Required
Not defined by default
Optional
By default, the ISP domain
name is included in the
username.
Optional
The defaults are as follows:
byte for data flows, and
one-packet for data packets.
Use either command
By default, the outbound port
serves as the source IP
address to send RADIUS
packets

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents