Command Manual – AAA&RADIUS&HWTACACS
H3C S3610&S5510 Series Ethernet Switches
Chapter 1 AAA & RADIUS & HWTACACS
Configuration Commands
1-43
Related command:
key
,
radius scheme
and
state
.
Example
# Set the IP address and UDP port number of the primary authentication/authorization
server used by the RADIUS scheme radius1 to 10.110.1.1 and 1812.
<Sysname> system-view
System View: return to User View with Ctrl+Z.
[Sysname] radius scheme radius1
New Radius scheme
[Sysname-radius-radius1] primary authentication 10.110.1.1 1812
1.2.12 radius client
Syntax
radius client enable
undo radius client
View
System view
Parameter
None
Description
Use the
radius client enable
command to enable the RADIUS client port.
Use the
undo radius client
command to disable the RADIUS client port.
By default, a RADIUS client port is enabled.
Note that:
z
After the RADIUS client port is disabled, for online users, Accounting-Request
(stop) packets can neither be sent nor be buffered. Meanwhile, the RADIUS server
cannot receive the packets of the online users going offline; in this case, an offline
user may remain connected to the server for a period of time. If the local device is
used as the RADIUS server, after the port is disabled, the number of connected
local users remains that before the port is disabled and cannot be updated
automatically.
z
After the RADIUS client port is disabled, if a local
authentication/authorization/accounting scheme is used for a new authentication
request, local authentication/authorization/accounting scheme is used if the
request fails RADIUS authentication.