422
C
HAPTER
21: 802.1
X
C
ONFIGURATION
The authorization information from the RADIUS server is sent to RADIUS clients in
authentication response packets, so you do not need to specify a separate
authorization server.
In real networking environments, you may specify two RADIUS servers as primary and
secondary authentication/authorization servers respectively, or specify one server to
function as both.
The RADIUS service port settings on the Switch 5500 should be consistent with the
port settings on the RADIUS server. Normally, the authentication/authorization service
port is 1812.
Configuring RADIUS
Accounting Servers and
the Related Attributes
Configuring RADIUS Accounting Servers
You can use the following commands to configure the IP address and port number for
RADIUS accounting servers.
Perform the following configurations in RADIUS Scheme View.
Table 452
Configuring RADIUS Accounting Servers
By default, as for the newly created RADIUS scheme, the IP address of the primary
accounting server is 0.0.0.0, and the UDP port number of this server is 1813; as for
the "system" RADIUS scheme created by the system, the IP address of the primary
accounting server is 127.0.0.1, and the UDP port number is 1646.
In real networking environments, you can specify two RADIUS servers as the primary
and the secondary accounting servers respectively; or specify one server to function as
both.
To guarantee the normal interaction between NAS and RADIUS server, you are
supposed to guarantee the normal routes between RADIUS server and NAS before
setting the IP address and UDP port of the RADIUS server. In addition, because
RADIUS protocol uses different UDP ports to receive/transmit
authentication/authorization and accounting packets, you need to set two different
ports accordingly. Suggested by RFC2138/2139, authentication/authorization port
number is 1812 and accounting port number is 1813. However, you may use values
other than the suggested ones. (Especially for some earlier RADIUS Servers,
authentication/authorization port number is often set to 1645 and accounting port
number is 1646.)
The RADIUS service port settings on the Switch 5500 units are supposed to be
consistent with the port settings on RADIUS server. Normally, RADIUS accounting
service port is 1813.
Operation
Command
Set IP address and port number of primary RADIUS
accounting server.
primary accounting
ip_address
[
port_number
]
Restore IP address and port number of primary RADIUS
accounting server to the default values.
undo primary accounting
Set IP address and port number of second RADIUS
accounting server.
secondary accounting
ip_address
[
port_number
]
Restore IP address and port number of second RADIUS
accounting server to the default values.
undo secondary accounting
Summary of Contents for 5500 SI - Switch - Stackable
Page 24: ...24 ABOUT THIS GUIDE...
Page 50: ...50 CHAPTER 1 GETTING STARTED...
Page 54: ...54 CHAPTER 2 ADDRESS MANAGEMENT CONFIGURATION...
Page 78: ...78 CHAPTER 3 PORT OPERATION...
Page 88: ...88 CHAPTER 4 XRN CONFIGURATION...
Page 122: ...122 CHAPTER 8 VLAN VPN CONFIGURATION...
Page 216: ...216 CHAPTER 15 SSH TERMINAL SERVICES...
Page 268: ...268 CHAPTER 16 IP ROUTING PROTOCOL OPERATION...
Page 308: ...308 CHAPTER 17 NETWORK PROTOCOL OPERATION...
Page 349: ...349...
Page 350: ...350 CHAPTER 18 MULTICAST PROTOCOL...
Page 522: ...522 CHAPTER 22 FILE SYSTEM MANAGEMENT...
Page 584: ...584 CHAPTER 30 PASSWORD CONTROL CONFIGURATION OPERATIONS...
Page 600: ...600 CHAPTER 31 MSDP CONFIGURATION...
Page 614: ...614 CHAPTER 32 CLUSTERING...
Page 670: ...670 CHAPTER C AUTHENTICATING THE SWITCH 5500 WITH CISCO SECURE ACS...