AAA and RADIUS Protocol Configuration
205
You can use the following command to set the supported types of RADIUS
servers. Perform the following configurations in RADIUS Scheme View.
Table 222
Setting the Supported Type of the RADIUS Server
By default, the newly created RADIUS scheme supports the server type
standard
,
while the "system" RADIUS scheme created by the system supports the server
type
3com
.
Setting the RADIUS
Server State
For the primary and secondary servers (no matter if they are an
authentication/authorization server or accounting server), if the primary server is
disconnected from the NAS for some fault, the NAS will automatically turn to
exchange packets with the secondary server. However, after the primary server
recovers, the NAS will not resume the communication with it at once, instead, it
continues communicating with the secondary server. When the secondary server
fails to communicate, the NAS will turn to the primary server again. The following
commands can be used to set the primary server to be
active
manually, in order
that NAS can communicate with it immediately after a fault has been resolved.
When the primary and secondary servers are both
active
or
block
, NAS will send
the packets to the primary server only.
Perform the following configurations in RADIUS Scheme View.
Table 223
Setting the RADIUS Server State
By default, for the newly created RADIUS scheme, the primary and secondary
accounting/authentication servers are in the state of
block
; for the "system"
RADIUS scheme created by the system, the primary accounting/authentication
servers are in the state of
active
, and the secondary accounting/authentication
servers are in the state of
block
.
Setting the Username
Format Transmitted to
the RADIUS Server
As mentioned above, the users are generally named in userid@isp-name format.
The part following “@” is the ISP domain name. The Switch will put the users into
different ISP domains according to the domain names. However, some earlier
RADIUS servers reject the username including ISP domain name. In this case, you
have to remove the domain name before sending the username to the RADIUS
server. The following command of switch decides whether the username to be
sent to RADIUS server carries ISP domain name or not.
Perform the following configurations in RADIUS Scheme View.
Operation
Command
Setting the Supported Type of RADIUS Server
server-type { 3com |
standard }
Restore the RADIUS server type to the default setting
undo server_type
Operation
Command
Set the state of primary RADIUS server
state primary { accounting |
authentication } { block | active }
Set the state of second RADIUS server
state secondary{ accounting |
authentication } { block | active }
Summary of Contents for 400 Family
Page 12: ......
Page 16: ...14 ABOUT THIS GUIDE ...
Page 58: ...56 CHAPTER 2 PORT OPERATION ...
Page 68: ...66 CHAPTER 3 VLAN OPERATION ...
Page 98: ...96 CHAPTER 5 NETWORK PROTOCOL OPERATION ...
Page 124: ...122 CHAPTER 6 IP ROUTING PROTOCOL OPERATION ...
Page 156: ...154 CHAPTER 8 ACL CONFIGURATION ...
Page 218: ...216 CHAPTER 11 802 1X CONFIGURATION ...
Page 298: ...296 CHAPTER 13 PASSWORD CONTROL CONFIGURATION OPERATIONS ...
Page 336: ...334 APPENDIX B RADIUS SERVER AND RADIUS CLIENT SETUP ...