Configuring Shared Keys For Radius Messages - H3C S3100-52P Operation Manual

Hide thumbs Also See for S3100-52P:
Table of Contents

Advertisement

Operation Manual – AAA
H3C S3100-52P Ethernet switch
Note:
In an actual network environment, you can specify one server as both the primary
and secondary accounting servers, as well as specifying two RADIUS servers as
the primary and secondary accounting servers respectively. In addition, because
RADIUS adopts different UDP ports to exchange authentication/authorization
messages and accounting messages, you must set a port number for accounting
different from that set for authentication/authorization.
With stop-accounting request buffering enabled, the switch first buffers the
stop-accounting request that gets no response from the RADIUS accounting server,
and then retransmits the request to the RADIUS accounting server until it gets a
response, or the maximum number of transmission attempts is reached (in this case,
it discards the request).
You can set the maximum allowed number of continuous real-time accounting
failures. If the number of continuously failed real-time accounting requests to the
RADIUS server reaches the set maximum number, the switch cuts down the user
connection.
The IP address and port number of the primary accounting server of the default
RADIUS scheme "system" are 127.0.0.1 and 1646 respectively.
Currently, RADIUS does not support the accounting of FTP users.

2.2.4 Configuring Shared Keys for RADIUS Messages

Both RADIUS client and server adopt MD5 algorithm to encrypt RADIUS messages
before they are exchanged between the two parties. The two parties verify the validity
of the RADIUS messages received from each other by using the shared keys that have
been set on them, and can accept and respond to the messages only when both parties
have the same shared key.
Follow these steps to configure shared keys for RADIUS messages:
Enter system view
Create a RADIUS scheme
and enter its view
Set a shared key for
RADIUS
authentication/authorizati
on messages
To do...
system-view
radius scheme
radius-scheme-name
key authentication string
Use the command...
2-16
Chapter 2 AAA Configuration
Remarks
Required
By default, a RADIUS
scheme named "system"
has already been created
in the system.
Required
By default, no shared key
is created.

Advertisement

Table of Contents
loading

Table of Contents