258
C
HAPTER
21: AAA C
ONFIGURATION
Configuring the
Attributes of Data to be
Sent to RADIUS Servers
n
■
Generally, the access users are named in the userid@isp-name format. Here,
isp-name after the "@" character represents the ISP domain name, by which
the device determines which ISP domain a user belongs to. However, some old
Create a RADIUS scheme and
enter its view
radius scheme
radius-scheme-name
Required
By default, a RADIUS scheme
named "system" has already
been created in the system.
Set the status of the primary
RADIUS
authentication/authorization
server
state primary
authentication
{
block
|
active
}
Optional
By default, the primary
RADIUS servers in the default
RADIUS scheme "system" are
in the
active
state, the
secondary servers in the
scheme are in the
block
state,
and all RADIUS servers in all
other RADIUS schemes are in
the
block
state.
Set the status of the primary
RADIUS accounting server
state primary accounting
{
block
|
active
}
Set the status of the
secondary RADIUS
authentication/authorization
server
state secondary
authentication
{
block
|
active
}
Set the status of the
secondary RADIUS accounting
server
state secondary accounting
{
block
|
active
}
Table 196
Set the status of RADIUS servers
Operation Command Remarks
Table 197
Configure the attributes of data to be sent to RADIUS servers
Operation
Command
Remarks
Enter system view
system-view
-
Create a RADIUS scheme and
enter its view
radius scheme
radius-scheme-name
Required
By default, a RADIUS scheme
named "system" has already
been created in the system.
Set the format of the user
names to be sent to RADIUS
server
user-name-format
{
with-domain
|
without-domain
}
Optional
By default, the user names
sent from the switch to
RADIUS server carry ISP
domain names.
Set the units of data flows to
RADIUS servers
data-flow-format data
{
byte
|
giga-byte
|
kilo-byte
|
mega-byte
}
packet
{
giga-packet
|
kilo-packet
|
mega- packet
|
one-packet
}
Optional
By default, in a RADIUS
scheme, the data unit and
packet unit for outgoing
RADIUS flows are byte and
one-packet respectively.
Set the MAC address format
of the Calling-Station-Id (Type
31) field in RADIUS packets
calling-station-id mode
{
mode1 | mode2
} {
lowercase | uppercase
}
Optional
By default, the MAC address
format is XXXX-XXXX-XXXX,
in lowercase.
Set the source IP address of
outgoing RADIUS messages
RADIUS scheme view
nas-ip
ip-address
Optional
By default, no source IP
address is set; and the IP
address of the corresponding
outbound interface is used as
the source IP address.
System view
radius nas-ip
ip-address
Содержание Switch 4210 9-Port
Страница 10: ...Password Control Configuration 556 Displaying Password Control 563 Password Control Configuration Example 564 ...
Страница 22: ...20 CHAPTER 1 CLI CONFIGURATION ...
Страница 74: ...72 CHAPTER 3 CONFIGURATION FILE MANAGEMENT ...
Страница 84: ...82 CHAPTER 5 VLAN CONFIGURATION ...
Страница 96: ...94 CHAPTER 8 IP PERFORMANCE CONFIGURATION ...
Страница 108: ...106 CHAPTER 9 PORT BASIC CONFIGURATION ...
Страница 122: ...120 CHAPTER 11 PORT ISOLATION CONFIGURATION ...
Страница 140: ...138 CHAPTER 13 MAC ADDRESS TABLE MANAGEMENT ...
Страница 234: ...232 CHAPTER 17 802 1X CONFIGURATION ...
Страница 246: ...244 CHAPTER 20 AAA OVERVIEW ...
Страница 270: ...268 CHAPTER 21 AAA CONFIGURATION ...
Страница 292: ...290 CHAPTER 26 DHCP BOOTP CLIENT CONFIGURATION ...
Страница 318: ...316 CHAPTER 29 MIRRORING CONFIGURATION ...
Страница 340: ...338 CHAPTER 30 CLUSTER ...
Страница 362: ...360 CHAPTER 33 SNMP CONFIGURATION ...
Страница 368: ...366 CHAPTER 34 RMON CONFIGURATION ...
Страница 450: ...448 CHAPTER 39 TFTP CONFIGURATION ...
Страница 451: ......
Страница 452: ...450 CHAPTER 39 TFTP CONFIGURATION ...
Страница 470: ...468 CHAPTER 40 INFORMATION CENTER ...
Страница 496: ...494 CHAPTER 44 DEVICE MANAGEMENT ...