Operation Manual – AAA
H3C S5100-SI/EI Series Ethernet Switches
Chapter 2 AAA Configuration
2-22
To do…
Use the command…
Remarks
Configure the parameters
of the local RADIUS
server
local-server nas-ip
ip-address key password
Required
By default, a local
RADIUS server is
configured with an NAS IP
address of 127.0.0.1.
Caution:
z
If you adopt the local RADIUS server function, the UDP port number of the
authentication/authorization server must be 1645, the UDP port number of the
accounting server must be 1646, and the IP addresses of the servers must be set to
the addresses of this switch.
z
The message encryption key set by the
local-server nas-ip
ip-address key
password
command must be identical with the authentication/authorization
message encryption key set by the
key authentication
command in the RADIUS
scheme view of the RADIUS scheme on the specified NAS that uses this switch as
its authentication server.
z
The switch supports IP addresses and shared keys for up to 16 network access
servers (NAS). That is, when acting as the local RADIUS server, the switch can
provide authentication service to up to 16 network access servers (including the
switch itself) at the same time.
z
When acting as the local RADIUS server, the switch does not support EAP
authentication.
2.2.10 Configuring Timers for RADIUS Servers
After sending out a RADIUS request (authentication/authorization request or
accounting request) to a RADIUS server, the switch waits for a response from the
server. The maximum time that the switch can wait for the response is called the
response timeout time of RADIUS servers, and the corresponding timer in the switch
system is called the response timeout timer of RADIUS servers. If the switch gets no
answer within the response timeout time, it needs to retransmit the request to ensure
that the user can obtain RADIUS service.
For the primary and secondary servers (authentication/authorization servers, or
accounting servers) in a RADIUS scheme:
When the switch fails to communicate with the primary server due to some server
trouble, the switch will turn to the secondary server and exchange messages with the
secondary server.