Command Manual – AAA&RADIUS&HWTACACS
H3C S3610&S5510 Series Ethernet Switches
Chapter 1 AAA & RADIUS & HWTACACS
Configuration Commands
1-42
[Sysname] radius scheme radius1
New Radius scheme
[Sysname-radius-radius1] primary accounting 10.110.1.2 1813
1.2.11 primary authentication
Syntax
primary authentication
ip-address
[
port-number
]
undo primary authentication
View
RADIUS scheme view
Parameter
ip-address
: IP address, in dotted decimal notation.
port-number
: UDP port number, ranging from 1 to 65535.
Description
Use the
primary authentication
command to set the IP address and port number of
the primary RADIUS authentication/authorization server.
Use the
undo primary authentication
command to restore the default IP address and
port number of the primary RADIUS authentication/authorization server.
By default, the system defines the RADIUS scheme system, with the IP address of the
primary accounting server as 127.0.0.1 and UDP port number as 1646; for a
newly-defined RADIUS scheme, the IP address of the primary accounting server is
127.0.0.1 and UDP port number is 1812.
Note that:
z
After creating a new RADIUS scheme, you should configure the IP address and
UDP port number of each RADIUS server you want to use in this scheme. These
RADIUS servers fall into two types: authentication/authorization, and accounting.
And for each kind of server, you can configure two servers in a RADIUS scheme:
primary and secondary servers. A RADIUS scheme has the following attributes: IP
addresses of the primary and secondary servers, shared keys, and types of the
RADIUS servers.
z
In an actual network environment, you can configure the above parameters as
required. But you should configure at least one authentication/authorization server
and one accounting server, and at the same time, you should keep the RADIUS
service port settings on the switch consistent with those on the RADIUS servers.
z
You are not allowed to assign the same IP address to both primary and secondary
authentication/authorization servers; otherwise, unsuccessful operation is
prompted