Operation Manual – AAA
H3C S3100 Series Ethernet Switches
Chapter 2 AAA Configuration
2-14
Operation
Command
Remarks
Set the IP address and
port number of the
primary RADIUS
authentication/authorizati
on server
primary authentication
ip-address
[
port-number
]
Required
By default, the IP address
and UDP port number of
the primary server are
0.0.0.0 and 1812
respectively for a newly
created RADIUS scheme.
Set the IP address and
port number of the
secondary RADIUS
authentication/authorizati
on server
secondary
authentication
ip-address
[
port-number
]
Optional
By default, the IP address
and UDP port number of
the secondary server are
0.0.0.0 and 1812
respectively for a newly
created RADIUS scheme.
Note:
z
The authentication response sent from the RADIUS server to the RADIUS client
carries authorization information. Therefore, you need not (and cannot) specify a
separate RADIUS authorization server.
z
In an actual network environment, you can specify one server as both the primary
and secondary authentication/authorization servers, as well as specifying two
RADIUS servers as the primary and secondary authentication/authorization servers
respectively.
z
The IP address and port number of the primary authentication server used by the
default RADIUS scheme "system" are 127.0.0.1 and 1645.
2.2.3 Configuring RADIUS Accounting Servers
Table 2-13
Configure RADIUS accounting servers
Operation
Command
Remarks
Enter system view
system-view
—
Create a RADIUS scheme
and enter its view
radius scheme
radius-scheme-name
Required
By default, a RADIUS
scheme named "system"
has already been created
in the system.