User Re-authentication at Reboot
425
The switch can automatically generate the main attributes (NAS-ID, NAS-IP and
session ID) of the Accounting-On packets. However, you can also manually configure
the NAS-IP attribute with the
nas-ip
command. When doing this, be sure to
configure a correct and valid IP address. If this attribute is not manually configured,
the switch will automatically select the IP address of the VLAN interface as the NAS-IP
address.
Configuring User
Re-authentication at
Reboot
Configuration Example
for User
Re-authentication at
Reboot
Network requirements
Enable user re-authentication at reboot.
Configuration procedure
1
Enter system view.
<S5500>
system-view
2
Enter the view of the RADIUS scheme named CAMS (supposing this scheme has
already existed).
[S5500]
radius scheme CAMS
3
Enable user re-authentication at reboot.
[S5500-radius-CAMS]
accounting-on enable
Setting the RADIUS
Packet Encryption Key
The RADIUS client (Switch system) and the RADIUS server use MD5 algorithm to
encrypt the exchanged packets. The two ends verify the packet through setting the
encryption key. Only when the keys are identical can both ends accept the packets
from each other and give responses.
You can use the following commands to set the encryption key for RADIUS packets.
Perform the following configurations in RADIUS Scheme View.
Table 458
Setting the RADIUS Packet Encryption Key
Table 457
Configure user re-authentication at reboot
Operation
Command
Description
Enter system view
system-view
—
Enter RADIUS scheme view
radius scheme
radius-scheme-name
—
Enable user re-authentication
at reboot
accounting-on enable
[
send
times
|
interval
interval
]
Optional
By default, this feature is disabled.
When this feature is enabled, the
system can send the Accounting-On
packet at most 15 times at intervals
of three seconds by default.
Operation
Command
Set RADIUS authentication/authorization packet
encryption key
key authentication
string
Restore the default RADIUS
authentication/authorization packet encryption key.
undo key authentication
Set RADIUS accounting packet key
key accounting
string
Restore the default RADIUS accounting packet key
undo key accounting
Summary of Contents for 5500 SI - Switch - Stackable
Page 24: ...24 ABOUT THIS GUIDE...
Page 50: ...50 CHAPTER 1 GETTING STARTED...
Page 54: ...54 CHAPTER 2 ADDRESS MANAGEMENT CONFIGURATION...
Page 78: ...78 CHAPTER 3 PORT OPERATION...
Page 88: ...88 CHAPTER 4 XRN CONFIGURATION...
Page 122: ...122 CHAPTER 8 VLAN VPN CONFIGURATION...
Page 216: ...216 CHAPTER 15 SSH TERMINAL SERVICES...
Page 268: ...268 CHAPTER 16 IP ROUTING PROTOCOL OPERATION...
Page 308: ...308 CHAPTER 17 NETWORK PROTOCOL OPERATION...
Page 349: ...349...
Page 350: ...350 CHAPTER 18 MULTICAST PROTOCOL...
Page 522: ...522 CHAPTER 22 FILE SYSTEM MANAGEMENT...
Page 584: ...584 CHAPTER 30 PASSWORD CONTROL CONFIGURATION OPERATIONS...
Page 600: ...600 CHAPTER 31 MSDP CONFIGURATION...
Page 614: ...614 CHAPTER 32 CLUSTERING...
Page 670: ...670 CHAPTER C AUTHENTICATING THE SWITCH 5500 WITH CISCO SECURE ACS...