313
Item Description
accounting server use the MD5 algorithm to encrypt packets exchanged
between them and use a shared key to verify the packets. Make sure the
HWTACACS server and client use the same shared key for secure
communication.
Quiet Time
Set the interval for which the primary server has to wait before being active.
If you leave this field blank, the default quiet interval is used.
Server Response Timeout
Time
Set the HWTACACS server response timeout time.
If the device does not receive any response from a server within the timeout
interval, it might tear down the connection with the server.
If you leave this field blank, the default response timeout period is used.
IMPORTANT:
HWTACACS is based on TCP. The timeout of the server response timeout
timer or the TCP timeout timer will cause the NAS to be disconnected from the
HWTACACS server.
Realtime Accounting
Interval
Set the realtime accounting interval. The value must be a multiple of 3.
Set a correct realtime accounting interval depending on the network
conditions. The device sends the accounting information of online users to the
HWTACACS server at the specified interval. According to the protocol, the
device does not disconnect the online users even if the server does not make
any responses.
If you leave this field blank, the default realtime accounting interval is used.
IMPORTANT:
Consider the performance of the NAS and the HWTACACS server when you
set the realtime accounting interval. A short interval requires higher
performance. Use a longer interval when the number of users exceeds 1000.
For the recommended ratios of the interval to the number of users, see
"
."
Buffer stop-accounting
packets
Specify whether to buffer the stop-accounting requests without responses in
the device.
Because stop-accounting requests affect the charge to users, a NAS must
make its best effort to send every stop-accounting request to the HWTACACS
accounting servers. For each stop-accounting request getting no response in
the specified period of time, the NAS buffers and resends the packet until it
receives a response or the number of transmission retries reaches the
configured limit. In the latter case, the NAS discards the packet.
Stop-Accounting Attempts
Set the maximum number of stop-accounting packet retransmission attempts
if no response is received for the stop-accounting packet.
The value for this field does not take effect if stop-accounting buffer is
disabled.
If you leave this field blank, the default maximum number is used.
HWTACACS Packet
Source IP
Specify the source IP address of HWTACACS packets sent to the
HWTACACS servers. Use a loopback interface address instead of a physical
interface address as the source IP address. This operation ensures that the
response packets from the servers can reach the device when the physical
interface is down.
Unit for Data Flows
Specify the measurement unit for data flows sent to the HWTACACS server
for traffic accounting. Options include:
•
Byte
(default).
•
Kilo-byte
.
•
Mega-byte
.
•
Giga-byte
.
Summary of Contents for FlexNetwork NJ5000
Page 12: ...x Index 440 ...
Page 39: ...27 Figure 16 Configuration complete ...
Page 67: ...55 Figure 47 Displaying the speed settings of ports ...
Page 78: ...66 Figure 59 Loopback test result ...
Page 158: ...146 Figure 156 Creating a static MAC address entry ...
Page 183: ...171 Figure 171 Configuring MSTP globally on Switch D ...
Page 243: ...231 Figure 237 IPv6 active route table ...