Operation Manual - Security
Quidway S3000-EI Series Ethernet Switches
Chapter 2 AAA and RADIUS Protocol
Configuration
Huawei Technologies Proprietary
2-10
2.3 Configuring RADIUS Protocol
For the Quidway Series Switches, the RADIUS protocol is configured on the per
RADIUS scheme basis. In real networking environment, a RADIUS scheme can be an
independent RADIUS server or a set of primary/second RADIUS servers with the same
configuration but two different IP addresses. Accordingly, attributes of every RADIUS
scheme include IP addresses of primary and second servers, shared key and RADIUS
server type etc.
Actually, RADIUS protocol configuration only defines some necessary parameters
using for information interaction between NAS and RADIUS Server. To make these
parameters effective, it is necessary to configure, in the view, an ISP domain to use the
RADIUS scheme and specify it to use RADIUS AAA schemes. For more about the
configuration commands, refer to the AAA Configuration section above.
RADIUS protocol configuration includes:
z
Creating/Deleting a RADIUS scheme
z
Setting IP Address and Port Number of RADIUS Server
z
Setting RADIUS packet encryption key
z
Setting response timeout timer of RADIUS server
z
Setting retransmission times of RADIUS request packet
z
Enabling the selection of RADIUS accounting option
z
Setting a real-time accounting interval
z
Setting maximum times of real-time accounting request failing to be responded
z
Enabling/Disabling stopping accounting request buffer
z
Setting the maximum retransmitting times of stopping accounting request
z
Setting the Supported Type of RADIUS Server
z
Setting RADIUS server state
z
Setting username format transmitted to RADIUS server
z
Setting the unit of data flow that transmitted to RADIUS server
z
Setting local RADIUS authentication server
Among the above tasks, creating RADIUS scheme and setting IP address of RADIUS
server are required, while other takes are optional and can be performed as per your
requirements.
2.3.1 Creating/Deleting a RADIUS scheme
As mentioned above, RADIUS protocol configurations are performed on the per
RADIUS scheme basis. Therefore, before performing other RADIUS protocol
configurations, it is compulsory to create the RADIUS scheme and enter its view to set
its IP address.
You can use the following commands to create/delete a RADIUS scheme.
Perform the following configurations in system view.