Operation Manual - Security
Quidway S3000 Series Ethernet Switches
Chapter 1 802.1x Configuration
1-12
[Quidway-radius-radius1] secondary authentication 10.11.1.2
[Quidway-radius-radius1] secondary accounting 10.11.1.1
# Set the encryption key when the system exchanges packets with the authentication
RADIUS server.
[Quidway-radius-radius1] key authentication name
# Set the encryption key when the system exchanges packets with the accounting
RADIUS server.
[Quidway-radius-radius1] key accounting money
# Set the timeouts and times for the system to retransmit packets to the RADIUS
server.
[Quidway-radius-radius1] timer 5
[Quidway-radius-radius1] retry 5
# Set the interval for the system to transmit real-time accounting packets to the
RADIUS server.
[Quidway-radius-radius1] timer realtime-accounting 15
# Configure the system to transmit the user name to the RADIUS server after removing
the domain name.
[Quidway-radius-radius1] user-name-format without-domain
[Quidway-radius-radius1] quit
# Create the user domain huawei163.net and enters isp configuration mode.
[Quidway] domain huawei163.net
# Specify radius1 as the RADIUS server group for the users in the domain
huawei163.net.
[Quidway-isp-huawei163.net] radius-scheme radius1
# Set a limit of 30 users to the domain huawei163.net.
[Quidway-isp-huawei163.net] access-limit enable 30
# Enable idle cut function for the user and set the idle cut parameter in the domain
huawei163.net.
[Quidway-isp-huawei163.net] idle-cut enable 20 2000
# Add a local supplicant and sets its parameter.
[Quidway] local-user localuser