6-17
RADIUS Authentication, Authorization, and Accounting
Configuring the Switch for RADIUS Authentication
Figure 6-5. Sample Configuration for RADIUS Server After Changing the Key and Adding Another Server
To change the order in which the switch accesses RADIUS servers, refer to
“Changing RADIUS-Server Access Order” on page 6-67.
4. Configure the Switch’s Global RADIUS Parameters
You can configure the switch for the following global RADIUS parameters:
■
Number of login attempts:
In a given session, specifies how many
tries at entering the correct username and password pair are allowed
before access is denied and the session terminated. (This is a general
aaa authentication
parameter and is not specific to RADIUS.)
■
Global server key:
The server key the switch will use for contacts
with all RADIUS servers for which there is not a server-specific key
configured by
radius-server host
<
ip-address
>
key
<
key-string
>
. This
key is optional if you configure a server-specific key for each RADIUS
server entered in the switch. (Refer to “3. Configure the Switch To
Access a RADIUS Server” on page 6-14.)
■
Server timeout:
Defines the time period in seconds for authentica-
tion attempts. If the timeout period expires before a response is
received, the attempt fails.
■
Server dead time:
Specifies the time in minutes during which the
switch avoids requesting authentication from a server that has not
responded to previous requests.
HP Switch(config)# radius-server host 10.33.18.127 key source0127
HP Switch(config)# radius-server host 10.33.18.119 key source0119
HP Switch(config)# show radius
Status and Counters - General RADIUS Information
Deadtime(min) : 0
Timeout(secs) : 5
Retransmit Attempts : 3
Global Encryption Key :myg10balkey
Dynamic Authorization UDP Port : 3799
Auth Acct DM/ Time
Server IP Addr Port Port CoA Window Encryption Key OOBM
--------------- ---- ---- --- ------ -------------------------------- -----
10.33.18.127 1812 1813 No 10 source0127 No
10.33.18.119 1812 1813 No 10 source0119 No
Changes
the key for
the existing
server to
“source012
7” (step 1,
above).
Adds the
new RADIUS
server with
its required
“source0119
” key.
Summary of Contents for E3800 Series
Page 2: ......
Page 3: ...HP Networking E3800 Switches Access Security Guide September 2011 KA 15 03 ...
Page 30: ...xxviii ...
Page 86: ...2 36 Configuring Username and Password Security Password Recovery ...
Page 186: ...4 72 Web and MAC Authentication Client Status ...
Page 364: ...8 32 Configuring Secure Shell SSH Messages Related to SSH Operation ...
Page 510: ...10 130 IPv4 Access Control Lists ACLs General ACL Operating Notes ...
Page 548: ...11 38 Configuring Advanced Threat Protection Using the Instrumentation Monitor ...
Page 572: ...12 24 Traffic Security Filters and Monitors Configuring Traffic Security Filters ...
Page 730: ...20 Index ...
Page 731: ......