![H3C S9500E Series Security Configuration Manual Download Page 40](http://html1.mh-extra.com/html/h3c/s9500e-series/s9500e-series_security-configuration-manual_3156952040.webp)
40
•
HP recommends that you specify only the primary RADIUS authentication/authorization server if backup
is not required.
•
If both the primary and secondary authentication/authorization servers are specified, the secondary one
is used when the primary one is unreachable.
•
In practice, you may specify one RADIUS server as the primary authentication/authorization server and
up to 16 RADIUS servers as the secondary authentication/authorization servers, or specify a RADIUS
server as the primary authentication/authorization server for a scheme and as the secondary
authentication/authorization server for another scheme at the same time.
•
The IP addresses of the primary and secondary authentication/authorization servers for a scheme must be
different from each other. Otherwise, the configuration fails.
•
All servers for authentication/authorization and accountings, primary or secondary, must use IP
addresses of the same IP version.
Specifying the RADIUS accounting servers and relevant
parameters
Follow these steps to specify the RADIUS accounting servers and perform related configurations:
To do…
Use the command…
Remarks
1.
Enter system view
system-view
—
2.
Enter RADIUS scheme view
radius scheme
radius-scheme-name
—
3.
Specify the primary RADIUS
accounting server
primary accounting
{
ip-address
[
port-number
|
key
string
|
vpn-
instance
vpn-instance-name
] * |
ipv6
ipv6-address
[
port-number
|
key
string
] * }
Required
Configure at least one of the
commands
No accounting server by
default
4.
Specify the secondary RADIUS
accounting server
secondary accounting
{
ip-address
[
port-number
|
key
string
|
vpn-
instance
vpn-instance-name
] *
|
ipv6
ipv6-address
[
port-number
|
key
string
] * }
5.
Enable the switch to buffer stop-
accounting requests getting no
responses
stop-accounting-buffer enable
Optional
Enabled by default
6.
Set the maximum number of
stop-accounting request
transmission attempts
retry stop-accounting
retry-times
Optional
500 by default
7.
Set the maximum number of
accounting request transmission
attempts
retry realtime-accounting
retry-
times
Optional
5 by default
•
It is recommended to specify only the primary RADIUS accounting server if backup is not required.