Configuring RADIUS Protocol
255
Configuring the Source
Address Used by NAS in
RADIUS Packets
Perform the following configuration in the corresponding view.
The effect of the two commands is the same. However, the configuration done in
RADIUS scheme view has a higher priority than the configuration done in system
view.
By default, no source address is specified, that is to say, the interface from which a
packet is sent is regarded as the source address of the packet.
Setting the Port State of
RADIUS Client
According to RFC2138/2139 protocol, Radius service generally adopts port 1812
as authentication packet port and port 1813 as accounting packet port. However,
the source port of both authentication packets and accounting packets is port
1812 on 3Com Switch 8800 Family series switches. If such packets are sent, the
destination port of the response packets is port 1812. So RADIUS service can be
controlled on the switch by controlling the inbound UDP packets whose
destination port is 1812.
3Com series switches provide the following command to set the state of port
1812 of the RADIUS client.
Perform the following configuration in system view.
The port 1812 of the RADIUS client is disabled by default.
If the port 1812 is disabled, all the UDP packets whose destination port is port
1812 will be dropped, so the remote RADIUS service cannot be used.
Configuring a Local
RADIUS Authentication
Server
3Com Switch 8800 Family series switches not only support the traditional RADIUS
client service mentioned above, that is, adopting authentication, authorization
and accounting servers to authenticate and administrate users, but also provides
simple local RADIUS server function (including authentication and authorization),
which is also known as local RADIUS authentication server function. A Switch
8800 Family switch supports up to 16 local RADIUS servers.
Perform the following configuration in system view.
Table 226
Configuring the source address used by the NAS in RADIUS packets
Operation
Command
Configure the source address used by the NAS
in RADIUS packets (RADIUS scheme view)
nas-ip
ip-address
Cancel the configured source address used by
the NAS in RADIUS packets (RADIUS scheme
view)
undo nas-ip
Configure the source address used by the NAS
in RADIUS packets (System view)
radius nas-ip
ip-address
[
vpn-instance
vpn-instance-name
]
Cancel the configured source address used by
the NAS in RADIUS packets (System view)
undo radius nas-ip
[
vpn-instance
vpn-instance-name
]
Table 227
Set the port state of RADIUS client
Operation
Command
Enable the port 1812 of the RADIUS client
radius client enable
Disable the port 1812 of the RADIUS client
undo radius client
Summary of Contents for Switch 8807
Page 14: ......
Page 32: ...32 CHAPTER 2 COMMAND LINE INTERFACE...
Page 50: ...50 CHAPTER 5 MANAGEMENT INTERFACE CONFIGURATION...
Page 54: ...54 CHAPTER 6 CONFIGURATION FILE MANAGEMENT...
Page 64: ...64 CHAPTER 8 SUPER VLAN CONFIGURATION...
Page 70: ...70 CHAPTER 9 ISOLATE USER VLAN CONFIGURATION...
Page 78: ...78 CHAPTER 10 IP ADDRESS CONFIGURATION...
Page 82: ...82 CHAPTER 11 IP PERFORMANCE CONFIGURATION flag ACK window 16079...
Page 100: ...100 CHAPTER 13 ETHERNET PORT CONFIGURATION...
Page 114: ...114 CHAPTER 15 PORT ISOLATION CONFIGURATION...
Page 158: ...158 CHAPTER 18 DIGEST SNOOPING CONFIGURATION...
Page 162: ...162 CHAPTER 19 FAST TRANSITION...
Page 219: ......
Page 220: ...220 CHAPTER 24 VLAN ACL CONFIGURATION...
Page 234: ...234 CHAPTER 25 802 1X CONFIGURATION...
Page 284: ...284 CHAPTER 28 IP ROUTING PROTOCOL OVERVIEW...
Page 290: ...290 CHAPTER 29 STATIC ROUTE CONFIGURATION...
Page 338: ...338 CHAPTER 31 OSPF CONFIGURATION...
Page 392: ...392 CHAPTER 33 BGP CONFIGURATION...
Page 404: ...404 CHAPTER 34 IP ROUTING POLICY CONFIGURATION...
Page 406: ...406 CHAPTER 35 ROUTE CAPACITY CONFIGURATION...
Page 408: ...408 CHAPTER 36 RECURSIVE ROUTING CONFIGURATION...
Page 416: ...416 CHAPTER 37 IP MULTICAST OVERVIEW...
Page 430: ...430 CHAPTER 39 IGMP SNOOPING CONFIGURATION...
Page 454: ...454 CHAPTER 42 IGMP CONFIGURATION...
Page 462: ...462 CHAPTER 43 PIM DM CONFIGURATION...
Page 506: ...506 CHAPTER 46 MBGP MULTICAST EXTENSION CONFIGURATION...
Page 528: ...528 CHAPTER 48 MPLS BASIC CAPABILITY CONFIGURATION...
Page 632: ...632 CHAPTER 51 MPLS VLL...
Page 652: ...652 CHAPTER 52 VPLS CONFIGURATION...
Page 666: ...666 CHAPTER 53 VRRP CONFIGURATION...
Page 680: ...680 CHAPTER 56 ARP TABLE SIZE CONFIGURATION...
Page 718: ...718 CHAPTER 59 NETSTREAM CONFIGURATION...
Page 728: ...728 CHAPTER 61 POE CONFIGURATION...
Page 736: ...736 CHAPTER 63 UDP HELPER CONFIGURATION...
Page 746: ...746 CHAPTER 64 SNMP CONFIGURATION...
Page 792: ...792 CHAPTER 68 FILE SYSTEM MANAGEMENT...
Page 800: ...800 CHAPTER 69 DEVICE MANAGEMENT...
Page 810: ...810 CHAPTER 70 FTP TFTP CONFIGURATION...
Page 840: ...840 CHAPTER 72 SYSTEM MAINTENANCE AND DEBUGGING...
Page 844: ...844 CHAPTER 74 PACKET STATISTICS CONFIGURATION...
Page 846: ...846 CHAPTER 75 ETHERNET PORT LOOPBACK DETECTION...
Page 860: ...860 CHAPTER 76 QINQ CONFIGURATION...
Page 866: ...866 CHAPTER 77 NQA CONFIGURATION...
Page 876: ...876 CHAPTER 78 PASSWORD CONTROL CONFIGURATION...