Radius Configuration; Creating A Radius Scheme - Huawei Quidway S3900 Series Operation Manual

Hide thumbs Also See for Quidway S3900 Series:
Table of Contents

Advertisement

Operation Manual – AAA & RADIUS & HWTACACS & EAD
Quidway S3900 Series Ethernet Switches-Release 1510

1.4 RADIUS Configuration

The RADIUS protocol configuration is performed on a RADIUS scheme basis. In an
actual network environment, you can either use a single RADIUS server or two
RADIUS servers (primary and secondary servers with the same configuration but
different IP addresses) in a RADIUS scheme. After creating a new RADIUS scheme,
you should configure the IP address and UDP port number of each RADIUS server you
want to use in this scheme. These RADIUS servers fall into two types:
authentication/authorization, and accounting. And for each kind of server, you can
configure two servers in a RADIUS scheme: primary server and secondary server. A
RADIUS scheme has the following attributes: IP addresses of the primary and
secondary servers, shared keys, and types of the RADIUS servers.
In an actual network environment, you can configure the above parameters as required.
But you should configure at least one authentication/authorization server and one
accounting server, and at the same time, you should keep the RADIUS service port
settings on the switch consistent with those on the RADIUS servers.
Note:
Actually, the RADIUS protocol configuration only defines the parameters used for
information exchange between the switch and the RADIUS servers. To make these
parameters take effect, you must reference the RADIUS scheme configured with these
parameters in an ISP domain view. For specific configuration commands, refer to
section 1.3 "AAA Configuration".

1.4.1 Creating a RADIUS Scheme

The RADIUS protocol configuration is performed on a RADIUS scheme basis. You
should first create a RADIUS scheme and enter its view before performing other
RADIUS protocol configurations.
Table 1-12 Create a RADIUS scheme
Operation
Enter system view
Create
scheme and enter its
view
system-view
a
RADIUS
radius
radius-scheme-name
Huawei Technologies Proprietary
Chapter 1 AAA & RADIUS & HWTACACS
Command
Required
scheme
By default, a RADIUS scheme
named "system" has already
been created in the system.
1-23
Configuration
Description

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents