![Huawei Quidway S3000-EI Series Operation Manual Download Page 239](http://html.mh-extra.com/html/huawei/quidway-s3000-ei-series/quidway-s3000-ei-series_operation-manual_169463239.webp)
Operation Manual - Security
Quidway S3000-EI Series Ethernet Switches
Chapter 2 AAA and RADIUS Protocol
Configuration
Huawei Technologies Proprietary
2-12
Operation
Command
Set IP address and port number of second
RADIUS accounting server.
secondary accounting
ip-address
[
port-number
]
Restore IP address and port number of
second RADIUS accounting server or server
to the default values.
undo secondary accounting
In real networking environments, the above parameters shall be set according to the
specific requirements. For example, you may specify 4 groups of different data to map
4 RADIUS servers, or specify one of the two servers as primary
authentication/authorization server and second accounting server and the other one as
second authentication/authorization server and primary accounting server, or you may
also set 4 groups of exactly same data so that every server serves as a primary and
second AAA server.
To guarantee the normal interaction between NAS and RADIUS server, you are
supposed to guarantee the normal routes between RADIUS server and NAS before
setting IP address and UDP port of the RADIUS server. In addition, because RADIUS
protocol uses different UDP ports to receive/transmit authentication/authorization and
accounting packets, you shall set two different ports accordingly. Suggested by
RFC2138/2139, authentication/authorization port number is 1812 and accounting port
number is 1813. However, you may use values other than the suggested ones.
(Especially for some earlier RADIUS Servers, authentication/authorization port number
is often set to 1645 and accounting port number is 1646.)
The RADIUS service port settings on Quidway Series Switches are supposed to be
consistent with the port settings on RADIUS server. Normally, RADIUS accounting
service port is 1813 and the authentication/authorization service port is 1812.
By default, all the IP addresses of primary/second authentication/authorization and
accounting servers are 0.0.0.0, authentication/authorization service port is 1812 and
accounting service UDP port is 1813.
2.3.3 Setting RADIUS Packet Encryption Key
RADIUS client (switch system) and RADIUS server use MD5 algorithm to encrypt the
exchanged packets. The two ends verify the packet through setting the encryption key.
Only when the keys are identical can both ends to accept the packets from each other
end and give response.
You can use the following commands to set the encryption key for RADIUS packets.
Perform the following configurations in RADIUS scheme view.