RADIUS Authentication and Accounting
Configuring RADIUS Accounting
Steps for Configuring RADIUS Accounting
1. Configure the switch for accessing a RADIUS server.
You can configure a list of up to three RADIUS servers (one primary, two
backup). The switch operates on the assumption that a server can operate
in both accounting and authentication mode. (Refer to the documentation
for your RADIUS server application.)
•
Use the same
radius-server host
command that you would use to
configure RADIUS authentication. Refer to “3. Configure the Switch
To Access a RADIUS Server” on page 6-13.
•
Provide the following:
–
A RADIUS server IP address.
–
Optional—a UDP destination port for authentication requests.
Otherwise the switch assigns the default UDP port (1812; recom
mended).
–
Optional—if you are also configuring the switch for RADIUS
authentication, and need a unique encryption key for use during
authentication sessions with the RADIUS server you are desig
nating, configure a server-specific key. This key overrides the
global encryption key you can also configure on the switch, and
must match the encryption key used on the specified RADIUS
server. For more information, refer to the “
[key < key-string >]
”
parameter on page 6-13. (Default: null)
2. Configure accounting types and the controls for sending reports to the
RADIUS server.
•
Accounting types:
exec (page 6-22), network (page 6-21), or system
(page 6-22)
•
Trigger for sending accounting reports to a RADIUS server:
At
session start and stop or only at session stop
3. (Optional) Configure session blocking and interim updating options
•
Updating:
Periodically update the accounting data for sessions-in-
progress
•
Suppress accounting:
Block the accounting session for any
unknown user with no username access to the switch
1. Configure the Switch To Access a RADIUS Server
Before you configure the actual accounting parameters, you should first
configure the switch to use a RADIUS server. This is the same as the process
described on page 6-13. You need to repeat this step here only if you have not
yet configured the switch to use a RADIUS server, your server data has
6-23
Содержание J8697A
Страница 1: ...6200yl Access Security Guide 5400zl 3500yl ProCurve Switches K 11 XX www procurve com ...
Страница 2: ......
Страница 22: ...Product Documentation Feature Index xx ...
Страница 55: ...Configuring Username and Password Security Front Panel Security 2 21 ...
Страница 56: ...Configuring Username and Password Security Front Panel Security 2 22 ...
Страница 58: ...Virus Throttling Contents Operating Notes 3 30 Connection Rate Log and Trap Messages 3 31 3 2 ...
Страница 88: ...Virus Throttling Connection Rate Log and Trap Messages This page is intentionally unused 3 32 ...
Страница 118: ...Web and MAC Authentication Client Status This page intentionally unused 4 30 ...
Страница 230: ...Configuring Secure Socket Layer SSL Common Errors in SSL setup This page is intentionally unused 8 22 ...
Страница 356: ...Configuring and Monitoring Port Security Operating Notes for Port Security 11 44 ...
Страница 370: ...Using Authorized IP Managers Operating Notes This page is intentionally unused 12 14 ...
Страница 388: ...10 Index ...
Страница 389: ......