23
Configuration task list
Tasks at a glance
Specifying the RADIUS authentication servers
Specifying the RADIUS accounting servers and the relevant parameters
Specifying the shared keys for secure RADIUS communication
Setting the username format and traffic statistics units
Setting the maximum number of RADIUS request transmission attempts
Setting the status of RADIUS servers
Specifying the source IP address for outgoing RADIUS packets
Configuring the accounting-on feature
Configuring the IP addresses of the security policy servers
Configuring the Login-Service attribute check method for SSH, FTP, and terminal users
Enabling SNMP notifications for RADIUS
Displaying and maintaining RADIUS
Creating a RADIUS scheme
Create a RADIUS scheme before performing any other RADIUS configurations. You can configure a
maximum of 16 RADIUS schemes. A RADIUS scheme can be used by multiple ISP domains.
To create a RADIUS scheme:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Create a RADIUS scheme and
enter RADIUS scheme view.
radius scheme
radius-scheme-name
The default setting depends on the
type of the startup configuration:
•
If the device starts up with initial
settings, no RADIUS scheme is
defined.
•
If the device starts up with the
default configuration file, a
RADIUS scheme named
system
is defined.
For more information about the
startup configuration, see
Fundamentals Configuration
Guide
.
Specifying the RADIUS authentication servers
A RADIUS authentication server completes authentication and authorization together, because
authorization information is piggybacked in authentication responses sent to RADIUS clients.