Configuring Shared Keys For Radius Packets - H3C S7500 Series Operation Manual

Hide thumbs Also See for S7500 Series:
Table of Contents

Advertisement

Operation Manual – AAA & RADIUS & HWTACACS & EAD
H3C S7500 Series Ethernet Switches
Caution:
In an actual network environment, you can either specify two RADIUS servers as
the primary and secondary accounting servers respectively, or specify only one
server as both the primary and secondary accounting servers. In addition, because
RADIUS uses different UDP ports to send/receive authentication/authorization
packets and the accounting packets, you need to set a port number for accounting
different from that set for authentication/authorization.
If the RADIUS server does not respond to such a request, the switch should first
buffer the request on itself, and then retransmit the request to the RADIUS
accounting server until it gets a response, or the maximum number of transmission
attempts is reached (in this case, it discards the request).
You can set the maximum number of real-time accounting request attempts in the
case that the accounting fails. If the switch makes all the allowed real-time
accounting request attempts but fails to perform accounting, it cuts down the
connection of the user.
The IP address and the port number of the default primary accounting server
system are 127.0.0.1 and 1646.
Currently, RADIUS does not support the accounting of FTP users.

1.4.4 Configuring Shared Keys for RADIUS Packets

The RADIUS client and server adopt MD5 algorithm to encrypt the RADIUS packets
exchanged with each other. The two parties verify the validity of the exchanged packets
by using the shared keys that have been set on them, and can accept and respond to
the packets sent from each other only if both of them have the same shared keys.
Table 1-15 Configure shared keys for RADIUS packets
Enter system view
Create a RADIUS scheme
and enter its view
Set a shared key for the
RADIUS
authentication/authorizati
on packets
To do...
system-view
radius scheme
radius-scheme-name
key authentication string
Chapter 1 AAA & RADIUS & HWTACACS
Use the command...
1-25
Configuration
Remarks
Required
By default, a RADIUS
scheme named system
has already been created
in the system.
Required

Advertisement

Table of Contents
loading

Table of Contents