Operation Manual – AAA&RADIUS
Quidway S3100 Series Ethernet Switches
Chapter 1 AAA&RADIUS Configuration
Huawei Technologies Proprietary
1-19
Operation
Command
Description
Create a RADIUS scheme
and enter its view
radius scheme
radius-scheme-na
me
Required
By default, a RADIUS
scheme named "system" has
already been created in the
system.
Set the IP address and port
number of the primary
RADIUS
authentication/authorization
server
primary
authentication
ip-address
[
port-number
]
Required
By default, the IP address and
UDP port number of the
primary server are 0.0.0.0
and 1812 respectively.
Set the IP address and port
number of the secondary
RADIUS
authentication/authorization
server
secondary
authentication
ip-address
[
port-number
]
Optional
By default, the IP address and
UDP port number of the
secondary server are 0.0.0.0
and 1812 respectively.
Caution:
z
The authentication response sent from the RADIUS server to the RADIUS client
carries the authorization information. Therefore, no separate authorization server
can be specified.
z
In an actual network environment, you can either specify two RADIUS servers as
the primary and secondary authentication/authorization servers respectively, or
specify only one server as both the primary and secondary
authentication/authorization servers.
z
The IP address and port number of the primary authentication server used by the
default RADIUS scheme "system" are 127.0.0.1 and 1645.
1.5.3 Configuring RADIUS Accounting Servers
Table 1-13
Configure RADIUS accounting server
Operation
Command
Description
Enter system view
system-view
—
Create a RADIUS
scheme and enter
its view
radius scheme
radius-scheme-name
Required
By default, a RADIUS scheme
named "system" has already
been created in the system.