1-27
z
It is recommended to specify only the primary RADIUS accounting server if backup is not required.
z
If both the primary and secondary accounting servers are specified, the secondary one is used
when the primary one is not reachable.
z
In practice, you can specify two RADIUS servers as the primary and secondary accounting servers
respectively, or specify one server to function as the primary accounting server in a scheme and
the secondary accounting server in another scheme. Besides, because RADIUS uses different
UDP ports to receive authentication/authorization and accounting packets, the port for
authentication/authorization must be different from that for accounting.
z
You can set the maximum number of stop-accounting request transmission buffer, allowing the
device to buffer and resend a stop-accounting request until it receives a response or the number of
transmission retries reaches the configured limit. In the latter case, the device discards the packet.
z
You can set the maximum number of accounting request transmission attempts on the device,
allowing the device to disconnect a user when the number of accounting request transmission
attempts for the user reaches the limit but it still receives no response to the accounting request.
z
The IP addresses of the primary and secondary accounting servers cannot be the same. Otherwise,
the configuration fails.
z
Currently, RADIUS does not support keeping accounts on FTP users.
z
All servers for authentication/authorization and accountings, primary or secondary, must use IP
addresses of the same IP version.
Setting the Shared Key for RADIUS Packets
The RADIUS client and RADIUS server use the MD5 algorithm to encrypt packets exchanged between
them and a shared key to verify the packets. Only when the same key is used can they properly receive
the packets and make responses.
Follow these steps to set the shared key for RADIUS packets:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Enter RADIUS scheme view
radius scheme
radius-scheme-name
—
Set the shared key for RADIUS
authentication/authorization or
accounting packets
key
{
accounting
|
authentication
}
string
Required
No key by default
The shared key configured on the device must be the same as that configured on the RADIUS server.
Содержание S7902E
Страница 82: ...1 4 DeviceA interface tunnel 1 DeviceA Tunnel1 service loopback group 1 ...
Страница 200: ...1 11 DeviceB display vlan dynamic No dynamic vlans exist ...
Страница 494: ...ii Displaying and Maintaining Tunneling Configuration 1 45 Troubleshooting Tunneling Configuration 1 45 ...
Страница 598: ...ii ...
Страница 1757: ...4 9 ...
Страница 1770: ...6 4 ...
Страница 2017: ...2 11 Figure 2 3 SFTP client interface ...
Страница 2062: ...i Table of Contents 1 URPF Configuration 1 1 URPF Overview 1 1 What is URPF 1 1 How URPF Works 1 1 Configuring URPF 1 2 ...
Страница 2238: ...1 16 DeviceA cfd linktrace service instance 1 mep 1001 target mep 4002 ...
Страница 2442: ...2 4 Set the interval for sending Syslog or trap messages to 20 seconds Device mac address information interval 20 ...