86
Parameters
ipv4-address
: Specifies an IPv4 address, which must be an address of the device. The IP address
cannot be 0.0.0.0, 255.255.255.255, a class D address, a class E address, or a loopback address.
ipv6
ipv6-address
: Specifies an IPv6 address, which must be a unicast address of the device and
cannot be a loopback address or a link-local address.
Usage guidelines
The source IP address of RADIUS packets that a NAS sends must match the IP address of the NAS
that is configured on the RADIUS server. A RADIUS server identifies a NAS by its IP address. Upon
receiving a RADIUS packet, a RADIUS server checks whether the source IP address of the packet is
the IP address of a managed NAS.
•
If the source IP address of the packet is the IP address of a managed NAS, the server
processes the packet.
•
If the source IP address of the packet is not the IP address of a managed NAS, the server drops
the packet.
As a best practice, specify a loopback interface address as the source IP address for outgoing
RADIUS packets to avoid RADIUS packet loss caused by physical port errors.
If you use both the
nas-ip
command and
radius nas-ip
command, the following guidelines apply:
•
The setting configured by using the
nas-ip
command in RADIUS scheme view applies only to
the RADIUS scheme.
•
The setting configured by using the
radius nas-ip
command in system view applies to all
RADIUS schemes.
•
The setting in RADIUS scheme view takes precedence over the setting in system view.
A RADIUS scheme can have only one source IPv4 address and one source IPv6 address for
outgoing RADIUS packets.
If you do not specify the
ipv6
keyword for the
undo nas-ip
command, the command deletes the
configured source IPv4 address for outgoing RADIUS packets.
Examples
# In RADIUS scheme
radius1
, specify IP address 10.1.1.1 as the source IP address for outgoing
RADIUS packets.
<Sysname> system-view
[Sysname] radius scheme radius1
[Sysname-radius-radius1] nas-ip 10.1.1.1
Related commands
display radius scheme
radius nas-ip
port
Use
port
to specify the RADIUS DAS port.
Use
undo port
to restore the default.
Syntax
port port-number
undo port
Default
The RADIUS DAS port number is 3799.
Содержание FlexNetwork 7500 Series
Страница 350: ...335 Related commands display port security port security enable ...
Страница 379: ...364 Sysname system view Sysname keychain abc mode absolute Sysname keychain abc tcp kind 252 ...
Страница 519: ...504 Related commands display ssh2 algorithm ssh2 algorithm cipher ssh2 algorithm key exchange ssh2 algorithm mac ...