1-28
To do…
Use the command…
Remarks
Enter system view
system-view
—
Enable the RADIUS trap
function
radius trap
{
accounting-server-down
|
authentication-server-down
}
Optional
Disabled by default
Create a RADIUS scheme and
enter RADIUS scheme view
radius scheme
radius-scheme-name
Required
Not defined by default
Specify the format of the
username to be sent to a
RADIUS server
user-name-format
{
keep-original
|
with-domain
|
without-domain
}
Optional
By default, the ISP domain
name is included in the
username.
Specify the unit for data flows or
packets to be sent to a RADIUS
server
data-flow-format
{
data
{
byte
|
giga-byte
|
kilo-byte
|
mega-byte
}
|
packet
{
giga-packet
|
kilo-packet
|
mega-packet
|
one-packet
} }*
Optional
The defaults are as follows:
byte
for data flows, and
one-packet
for data packets.
In RADIUS
scheme view
nas-ip ip-address
quit
Set the
source IP
address of the
device to
send RADIUS
packets
In system view
radius nas-ip ip-address
Use either command
By default, the outbound port
serves as the source IP
address to send RADIUS
packets
z
Some earlier RADIUS servers cannot recognize usernames that contain an ISP domain name. In
this case, the device must remove the domain name before sending a username including a
domain name. You can configure the
user-name-format
without-domain
command on the
device for this purpose.
z
If a RADIUS scheme defines that the username is sent without the ISP domain name, do not apply
the RADIUS scheme to more than one ISP domain, thus avoiding the confused situation where the
RADIUS server regards two users in different ISP domains but with the same userid as one.
z
The unit of data flows sent to the RADIUS server must be consistent with the traffic statistics unit of
the RADIUS server. Otherwise, accounting cannot be performed correctly.
z
The
nas-ip
command in RADIUS scheme view is only for the current RADIUS scheme, while the
radius nas-ip
command in system view is for all RADIUS schemes. However, the
nas-ip
command in RADIUS scheme view takes precedence over the
radius nas-ip
command.
Setting Timers Regarding RADIUS Servers
When communicating with the RADIUS server, a device can enable the following three timers:
z
RADIUS server response timeout (
response-timeout
): If a NAS receives no response from the
RADIUS server in a period of time after sending a RADIUS request (authentication/authorization or
accounting request), it has to resend the request so that the user has more opportunity to obtain
the RADIUS service. The NAS uses the RADIUS server response timeout timer to control the
transmission interval.
Summary of Contents for S5500-SI Series
Page 161: ...3 10 GigabitEthernet1 0 1 2 MANUAL...
Page 220: ...1 7 Clearing ARP entries from the ARP table may cause communication failures...
Page 331: ...1 7 1 1 ms 1 ms 1 ms 1 1 6 1 2 1 ms 1 ms 1 ms 1 1 4 1 3 1 ms 1 ms 1 ms 1 1 2 2 Trace complete...
Page 493: ...2 8...
Page 1111: ...1 10 Installing patches Installation completed and patches will continue to run after reboot...