![H3C SR8800-F Скачать руководство пользователя страница 42](http://html2.mh-extra.com/html/h3c/sr8800-f/sr8800-f_configuration-manual_4025863042.webp)
26
Step Command
Remarks
3.
Specify RADIUS accounting
servers.
•
Specify the primary RADIUS
accounting server:
primary accounting
{
ipv4-address
|
ipv6
ipv6-address
} [
port-number
|
key
{
cipher
|
simple
}
string
|
vpn-instance
vpn-instance-name
|
weight
weight-value
] *
•
Specify a secondary RADIUS
accounting server:
secondary accounting
{
ipv4-address
|
ipv6
ipv6-address
} [
port-number
|
key
{
cipher
|
simple
}
string
|
vpn-instance
vpn-instance-name
|
weight
weight-value
] *
By default, no accounting
servers are specified.
Two accounting servers in a
scheme, primary or
secondary, cannot have the
same combination of IP
address, port number, and
VPN instance.
The
weight
weight-value
option takes effect only when
the RADIUS server load
sharing feature is enabled for
the RADIUS scheme.
Specifying the shared keys for secure RADIUS
communication
The RADIUS client and server use the MD5 algorithm and shared keys to generate the Authenticator
value for packet authentication and user password encryption. The client and server must use the
same key for each type of communication.
A key configured in this task is for all servers of the same type (accounting or authentication) in the
scheme. The key has a lower priority than a key configured individually for a RADIUS server.
To specify a shared key for secure RADIUS communication:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter RADIUS scheme
view.
radius scheme
radius-scheme-name
N/A
3.
Specify a shared key for
secure RADIUS
communication.
key
{
accounting
|
authentication
} {
cipher
|
simple
}
string
By default, no shared key is
specified for secure RADIUS
communication.
The shared key configured on the
device must be the same as the
shared key configured on the
RADIUS server.
Specifying an MPLS L3VPN instance for the scheme
The VPN instance specified for a RADIUS scheme applies to all authentication and accounting
servers in that scheme. If a VPN instance is also configured for an individual RADIUS server, the
VPN instance specified for the RADIUS scheme does not take effect on that server.
To specify a VPN instance for a scheme:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter RADIUS scheme view.
radius scheme
radius-scheme-name
N/A