Command Manual – AAA&RADIUS&HWTACACS
H3C S3610&S5510 Series Ethernet Switches
Chapter 1 AAA & RADIUS & HWTACACS
Configuration Commands
1-38
[Sysname] radius scheme radius1
New Radius scheme
[Sysname-radius-radius1] key accounting ok
1.2.7 local-server
Syntax
local-server nas-ip ip-address key password
undo local-server nas-ip ip-address
View
System view
Parameter
nas-ip ip-address
: Specifies the IP address of the local RADIUS server. Where,
ip-address
is in dotted decimal notation.
key password
: Specifies the shared key of the authentication server and access server.
Where,
password
is a character string of up to 16 characters.
Description
Use the
local-server
command to create a local RADIUS authentication server (that is,
set the related parameters of the server).
Use the
undo local-server
command to delete the specified local RADIUS
authentication server.
By default, a local RADIUS authentication server, with NAS-IP 127.0.0.1, has already
been created.
Note that:
z
The switch not only supports the traditional RADIUS client service to accomplish
user AAA management through foreign authentication/authorization server and
accounting server, but also provides a simple local RADIUS server function for
authentication and authorization. This function is called local RADIUS
authentication server function.
z
When you use the local RADIUS authentication server function, the UDP port
number for the authentication/authorization service must be 1645, the UDP port
number for the accounting service is 1646.
z
The packet encryption key set by the
local-server
command with the
key
password
parameter must be identical with the authentication/authorization
packet encryption key set by the
key authentication
command in RADIUS
scheme view.
z
The switch supports at most 16 IP addresses and shared keys of the network
access server (including the default local RADIUS authentication server); that is,