![Huawei Quidway S5600 Operation Manual Download Page 561](http://html.mh-extra.com/html/huawei/quidway-s5600/quidway-s5600_operation-manual_169841561.webp)
Operation Manual – AAA & RADIUS & HWTACACS & EAD
Quidway S5600 Series Ethernet Switches-Release 1510
Chapter 1 AAA & RADIUS & HWTACACS
Configuration
Huawei Technologies Proprietary
1-31
Caution:
z
When you use the local RADIUS authentication server function, the UDP port
number for the authentication/authorization service must be 1645, the UDP port
number for the accounting service is 1646, and the IP addresses of the servers must
be set to the addresses of the switch.
z
The packet encryption key set by the
local-server
command with the
key password
parameter must be identical with the authentication/authorization packet encryption
key set by the
key authentication
command in RADIUS scheme view.
z
The switch supports up to 16 local RADIUS authentication servers (including the
default local RADIUS authentication server).
1.4.10 Configuring the Timers of RADIUS Servers
If the switch gets no response from the RADIUS server after sending out a RADIUS
request (authentication/authorization request or accounting request) and waiting for a
period of time, it should retransmit the packet to ensure that the user can obtain the
RADIUS service. This wait time is called response timeout time of RADIUS servers;
and the timer in the switch system that is used to control this wait time is called the
response timeout timer of RADIUS servers.
For the primary and secondary servers (authentication/authorization servers, or
accounting servers) in a RADIUS scheme:
When the switch fails to communicate with the primary server due to some server
trouble, the switch will actively exchange packets with the secondary server.
After the time the primary server keeps in the block state exceeds the time set with the
timer quiet
command, the switch will try to communicate with the primary server again
when it has a RADIUS request. If the primary server recovers, the switch immediately
restores the communication with the primary server instead of communicating with the
secondary server, and at the same time restores the primary server to the active state
while keeping the state of the secondary server unchanged.
To charge the users in real time, you should set the interval of real-time accounting.
After the setting, the switch sends the accounting information of online users to the
RADIUS server at regular intervals.
Table 1-21
Set the timers of RADIUS server
Operation
Command
Description
Enter system
view
system-view
—