61
[Sysname] radius scheme radius1
[Sysname-radius-radius1] key accounting simple ok
# For RADIUS scheme
radius1
, set the shared key for secure accounting communication to
ok
in
plain text.
<Sysname> system-view
[Sysname] radius scheme radius1
[Sysname-radius-radius1] key accounting ok
# For RADIUS scheme
radius1
, set the shared key for secure authentication/authorization
communication to
$c$3$NMCbVjyIutaV6csCOGp4zsKRTlg2eT3B
in cipher text.
<Sysname> system-view
[Sysname] radius scheme radius1
[Sysname-radius-radius1] key authentication cipher
$c$3$NMCbVjyIutaV6csCOGp4zsKRTlg2eT3B
Related commands
display radius scheme
nas-ip (RADIUS scheme view)
Use
nas-ip
to specify a source IP address for outgoing RADIUS packets.
Use
undo nas-ip
to restore the default.
Syntax
nas-ip
{
ipv4-address
|
ipv6
ipv6-address
}
undo nas-ip
Default
The source IP address of an outgoing RADIUS packet is that configured by the
radius nas-ip
command in system view. If the
radius nas-ip
command is not configured, the source IP address is
the IP address of the outbound interface.
Views
RADIUS scheme view
Default command level
2: System level
Parameters
ipv4-address
: IPv4 address in dotted decimal notation. It must be an address of the device and
cannot be 0.0.0.0, 255.255.255.255, a class D address, or a class E address.
ipv6
ipv6-address
: Specifies an IPv6 address. It must be a unicast address of the device and cannot
be a link-local address.
Usage guidelines
The source IP address of RADIUS packets that a NAS sends must match the IP address of the NAS
that is configured on the RADIUS server. A RADIUS server identifies a NAS by its IP address. Upon
receiving a RADIUS packet, a RADIUS server checks whether the source IP address of the packet is
the IP address of any managed NAS. If it is, the server processes the packet. If it is not, the server
drops the packet.
The source IP address specified for outgoing RADIUS packets must be of the same IP version as the
IP addresses of the RADIUS servers in the RADIUS scheme. Otherwise, the source IP address
configuration does not take effect.