40
{
Change the authorization information of specific online users.
{
Shut down and then bring up the access interfaces of users.
Procedure
To configure the RADIUS DAS feature:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enable the RADIUS DAS
feature and enter RADIUS
DAS view.
radius dynamic-author server
By default, the RADIUS DAS
feature is disabled.
3.
Specify a RADIUS DAC.
client
{
ip ipv4-address
|
ipv6
ipv6-address
} [
key
{
cipher
|
simple
}
string
|
vpn-instance
vpn-instance-name
] *
By default, no RADIUS DACs are
specified.
4.
Specify the RADIUS DAS
port.
port
port-number
By default, the RADIUS DAS port is
3799.
Changing the DSCP priority for RADIUS packets
The DSCP priority in the ToS field determines the transmission priority of RADIUS packets. A larger
value represents a higher priority.
To change the DSCP priority for RADIUS packets:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Change the DSCP priority
for RADIUS packets.
radius
[
ipv6
]
dscp
dscp-value
By default, the DSCP priority is 0
for RADIUS packets.
Configuring the device to preferentially process RADIUS
authentication requests
About configuring the device to preferentially process RADIUS authentication requests
RADIUS requests include RADIUS authentication requests, RADIUS accounting-start requests,
RADIUS accounting-update requests, and RADIUS accounting-stop requests. By default, the device
processes the RADIUS requests in the sequence that the requests are initiated.
When a large number of users go offline and then try to come online immediately, authentication
might fail for these users because of authentication request timeout. To resolve this issue, configure
the device to preferentially process authentication requests.
Restrictions and guidelines
Do not perform this task if the RADIUS server identifies users by the username and does not allow
repeated authentication for the same username. A violation might cause authentication failure for
users that try to come online immediately after going offline.
As a best practice, do not perform this task when the device has online users.
Procedure
To configure the device to preferentially process RADIUS authentication requests: