7-5
Redundancy and Backup for RADIUS Services
Redundancy
Configure the NASs
To provide redundancy for RADIUS services, you must specify at least two
RADIUS servers on each NAS. If the first RADIUS server listed is unavailable,
the NAS contacts the second RADIUS server.
Best practices dictate that you specify one RADIUS server as the primary
server for some NASs and the other RADIUS server as the primary server for
other NASs. Each RADIUS server, of course, acts as the secondary server for
the NASs for which it is not the primary server. This design eases the burden
on each RADIUS server; during normal conditions, each handles only some
of the authentication requests.
For example, when you configure port authentication on the ProCurve Switch
5400zl Series, you specify a RADIUS server using the following command:
ProCurve Switch (config)# radius-server host <ip address>
To configure a primary and a secondary RADIUS server, you simply enter the
command twice: the first time you enter the IP address for the primary
RADIUS server; the second time you enter the IP address for the secondary
RADIUS server. The 5400zl Switch will contact the RADIUS servers in the
order in which they are listed in the running-config.
Figure 7-2 shows a sample running-config for a 5400zl Switch. In this example,
two RADIUS servers are listed. Both of these servers are NAC 800s. When the
switch receives an authentication request, it will contact the first RADIUS
server listed—in this case, the NAC 800 with the IP address 10.1.1.20. If that
server does not respond, the 5400zl Switch will contact the next RADIUS
server listed—10.1.1.100 in the example.
On another switch, you might reverse the order of the commands, specifying
10.1.1.100 before 10.1.1.20.
Summary of Contents for 800
Page 1: ...Configuration Guide www procurve com ProCurve Network Access Controller 800 ...
Page 2: ......
Page 3: ...ProCurve Network Access Controller 800 Configuration Guide April 2008 1 0 30398 ...
Page 74: ...1 62 Overview of the ProCurve NAC 800 Deployment Methods ...
Page 155: ...3 27 Initial Setup of the ProCurve NAC 800 System Settings ...
Page 194: ...3 66 Initial Setup of the ProCurve NAC 800 Digital Certificates ...
Page 336: ...6 8 Disabling Endpoint Integrity Testing Overview ...
Page 354: ...7 18 Redundancy and Backup for RADIUS Services Back Up Your NAC 800 Configuration ...
Page 380: ...A 26 Appendix A Glossary ...
Page 394: ...B 14 Appendix B Linux Commands Service Commands ...
Page 405: ......