Operation Manual - Security
Quidway S3000 Series Ethernet Switches
Chapter 2 AAA and RADIUS Protocol Configuration
2-16
2.3.14 Configure Local RADIUS Server Group
RADIUS service, which adopts authentication/authorization/accounting servers to
manage users, is widely used in Huawei Quidway series switches. Besides, local
authentication/authorization/accounting service is also used in these products and it is
called local RADIUS function, i.e. realize basic RADIUS function on the switch.
Perform the following commands in system view to create/delete local RADIUS server
group.
Table 2-21
Create/Delete local RADIUS server group
Operation Command
Create local RADIUS server group
and enter its view
local-radius nas-ip
ip-address
key
password
Delete local RADIUS server group
undo local-radius nas-ip
ip-address
By default, the IP address of local RADIUS server group is 127.0.0.1 and the password
is Huawei.
When using local RADIUS server function of Huawei, remember the number of UDP
port used for authentication is 1645 and that for authorization is 1646.
2.4 Display and Debug AAA and RADIUS Protocol
After the above configuration, execute
display
command in any view to display the
running of the AAA and RADIUS configuration, and to verify the effect of the
configuration. Execute
reset
command in user view to reset AAA and RADIUS
configuration . Execute
debugging
command in user view to debug AAA and RADIUS.
Table 2-22
Display and debug AAA and RADIUS protocol
Operation
Command
Display the configuration information of
the specified or all the ISP domains.
display domain
[
isp-name
]
Display related information of user’s
connection
display connection
{
access-type
{
dot1x
|
gcm
} |
domain
isp-name
|
interface
interface-type
interface-number
|
ip
ip-address
|
mac
mac-address
|
radius-scheme
radius-scheme-name
|
vlan
vlanid
|
ucibindex
ucib-index
|
user-name
user-name
}
Display related information of the local
user ( All S3000 series switches
support SSH except S3026)
display local-user
[
domain
isp-name
|
idle-cut
{
disable
|
enable
} |
service-type
{
telnet
|
ftp
|
lan-access
|
ssh
} |
state
{
active
|
block
} |
user-name
user-name
|
vlan
vlan
-id
]
Display information of local RADIUS
server group
display local-server statistics