85
•
When the RADIUS server load sharing feature is disabled, the device tries to communicate with
an active server that has the highest priority for authentication.
•
When the RADIUS server load sharing feature is enabled, the device performs the following
operations:
a.
Checks the weight value and number of currently served users for each active server.
b.
Determines the most appropriate server in performance to receive an AAA request.
Examples
# In RADIUS scheme
radius1
, specify the primary authentication server with IP address 10.110.1.1,
UDP port number 1812, and plaintext shared key
123456TESTauth&!
.
<Sysname> system-view
[Sysname] radius scheme radius1
[Sysname-radius-radius1] primary authentication 10.110.1.1 1812 key simple
123456TESTauth&!
Related commands
display radius scheme
key
(RADIUS scheme view)
radius-server test-profile
secondary authentication
(RADIUS scheme view)
server-load-sharing enable
vpn-instance
(RADIUS scheme view)
radius attribute extended
Use
radius attribute extended
to define an extended RADIUS attribute.
Use
undo radius attribute extended
to delete user-defined extended RADIUS attributes.
Syntax
radius attribute extended attribute-name
[
vendor
vendor-id
]
code
attribute-code
type
{
binary
|
date
|
integer
|
interface-id
|
ip
|
ipv6
|
ipv6-prefix
|
octets
|
string
}
undo radius attribute extended
[
attribute-name
]
Default
No user-defined extended RADIUS attributes exist.
Views
System view
Predefined user roles
network-admin
Parameters
attribute-name
: Specifies the RADIUS attribute name, a case-insensitive string of 1 to 63
characters. The name must be unique among all RADIUS attributes, including the standard and
extended RADIUS attributes.
vendor
vendor-id
: Specifies a vendor ID in the range of 1 to 65535. If you do not specify a
vendor ID, the device processes the RADIUS attribute as a standard RADIUS attribute.
Summary of Contents for SOHO IE4300
Page 285: ...i Contents Tcl commands 1 cli 1 tclquit 1 tclsh 2...
Page 288: ...i Contents Python commands 1 exit 1 python 1 python filename 2...
Page 291: ...i Contents Automatic configuration commands 1 autodeploy udisk enable 1...
Page 323: ...25 Sysname Ten GigabitEthernet1 0 51 undo shutdown Related commands irf port...
Page 465: ...ii stp vlan enable 55 vlan mapping modulo 55...
Page 602: ...12 Related commands display mvrp statistics...
Page 609: ...i Contents VLAN mapping commands 1 display vlan mapping 1 vlan mapping 2...
Page 678: ...9 Related commands reset pppoe relay statistics...
Page 846: ...i Contents Basic IP forwarding commands 1 display fib 1 ip forwarding table save 2...
Page 1770: ...i Contents Time range commands 1 display time range 1 time range 1...
Page 2026: ...34 Related commands display mac authentication...
Page 2028: ...ii...
Page 2143: ...i Contents User profile commands 1 display user profile 1 user profile 2...
Page 2308: ...61 ipsec transform set...
Page 2531: ...i Contents SAVI commands 1 ipv6 savi down delay 1 ipv6 savi log enable 1 ipv6 savi strict 2...
Page 2534: ...3 Sysname ipv6 savi strict Related commands ipv6 verify source...
Page 2791: ...14 Sysname track 1 Related commands delay display track...
Page 2939: ...9 sntp authentication keyid sntp reliable authentication keyid...
Page 2967: ...27 Related commands apply poe profile poe enable poe max power interface view poe priority...