RADIUS Configuration Task List
255
■
In an actual network environment, you can specify one server as both the
primary and secondary authentication/authorization servers, as well as
specifying two RADIUS servers as the primary and secondary
authentication/authorization servers respectively.
■
The IP address and port number of the primary authentication server used by
the default RADIUS scheme "system" are 127.0.0.1 and 1645.
Configuring RADIUS
Accounting Servers
n
■
In an actual network environment, you can specify one server as both the
primary and secondary accounting servers, as well as specifying two RADIUS
servers as the primary and secondary accounting servers respectively. In
addition, because RADIUS adopts different UDP ports to exchange
authentication/authorization messages and accounting messages, you must set
a port number for accounting different from that set for
authentication/authorization.
Table 192
Configure RADIUS accounting servers
Operation
Command
Remarks
Enter system view
system-view
-
Create a RADIUS scheme and
enter its view
radius scheme
radius-scheme-name
Required
By default, a RADIUS scheme
named "system" has already
been created in the system.
Set the IP address and port
number of the primary
RADIUS accounting server
primary accounting
ip-address
[
port-number
]
Required
By default, the IP address and
UDP port number of the
primary accounting server are
0.0.0.0 and 1813 for a newly
created RADIUS scheme.
Set the IP address and port
number of the secondary
RADIUS accounting server
secondary
accounting
ip-address
[
port-number
]
Optional
By default, the IP address and
UDP port number of the
secondary accounting server
are 0.0.0.0 and 1813 for a
newly created RADIUS
scheme.
Enable stop-accounting
request buffering
stop-accounting-buffer
enable
Optional
By default, stop-accounting
request buffering is enabled.
Set the maximum number of
transmission attempts of a
buffered stop-accounting
request.
retry stop-accounting
retry-times
Optional
By default, the system tries at
most 500 times to transmit a
buffered stop-accounting
request.
Set the maximum allowed
number of continuous
real-time accounting failures
retry realtime-accounting
retry-times
Optional
By default, the maximum
allowed number of
continuous real-time
accounting failures is five. If
five continuous failures occur,
the switch cuts down the user
connection.
Summary of Contents for Switch 4210 9-Port
Page 22: ...20 CHAPTER 1 CLI CONFIGURATION ...
Page 74: ...72 CHAPTER 3 CONFIGURATION FILE MANAGEMENT ...
Page 84: ...82 CHAPTER 5 VLAN CONFIGURATION ...
Page 96: ...94 CHAPTER 8 IP PERFORMANCE CONFIGURATION ...
Page 108: ...106 CHAPTER 9 PORT BASIC CONFIGURATION ...
Page 122: ...120 CHAPTER 11 PORT ISOLATION CONFIGURATION ...
Page 140: ...138 CHAPTER 13 MAC ADDRESS TABLE MANAGEMENT ...
Page 234: ...232 CHAPTER 17 802 1X CONFIGURATION ...
Page 246: ...244 CHAPTER 20 AAA OVERVIEW ...
Page 270: ...268 CHAPTER 21 AAA CONFIGURATION ...
Page 292: ...290 CHAPTER 26 DHCP BOOTP CLIENT CONFIGURATION ...
Page 318: ...316 CHAPTER 29 MIRRORING CONFIGURATION ...
Page 340: ...338 CHAPTER 30 CLUSTER ...
Page 362: ...360 CHAPTER 33 SNMP CONFIGURATION ...
Page 368: ...366 CHAPTER 34 RMON CONFIGURATION ...
Page 450: ...448 CHAPTER 39 TFTP CONFIGURATION ...
Page 451: ......
Page 452: ...450 CHAPTER 39 TFTP CONFIGURATION ...
Page 470: ...468 CHAPTER 40 INFORMATION CENTER ...
Page 496: ...494 CHAPTER 44 DEVICE MANAGEMENT ...