24
To do…
Command…
Remarks
3.
Specify a shared key for
authenticating RADIUS
authentication/authorization
or accounting packets.
key
{
accounting
|
authentication
}
string
Required
No shared key by default
NOTE:
A shared key configured on the router must be the same as that configured on the RADIUS server.
Specifying the VPN to which the servers belongs
After you specify a VPN for a RADIUS scheme, all the authentication/authorization/accounting servers
specified for the scheme belong to the VPN. However, if you also specify a VPN when specifying a
server for the scheme, the server belongs to the specific VPN.
To specify a VPN for a RADIUS scheme:
To do…
Command…
Remarks
1.
Enter system view.
system-view
—
2.
Enter RADIUS scheme view.
radius scheme
radius-scheme-name
—
3.
Specify a VPN for the
RADIUS scheme.
vpn-instance
vpn-instance-name
Required
Setting the supported RADIUS server type
The supported RADIUS server type determines the type of the RADIUS protocol that the router uses to
communicate with the RADIUS server. It can be standard or extended:
•
Standard
—Uses the standard RADIUS protocol, compliant with RFC 2865 and RFC 2866 or later.
•
Extended
—Uses the proprietary RADIUS protocol of HP.
When the RADIUS server runs iMC, you must set the RADIUS server type to
extended
. When the RADIUS
server runs third-party RADIUS server software, either RADIUS server type applies. For the router to
function as a RADIUS server to authenticate login users, you must set the RADIUS server type to
standard
.
To set the RADIUS server type:
To do…
Command…
Remarks
1.
Enter system view.
system-view
—
2.
Enter RADIUS scheme view.
radius scheme
radius-scheme-
name
—
3.
Set the RADIUS server type.
server-type
{
extended
|
standard
}
Optional
standard
by default
NOTE:
Changing the RADIUS server type restores the unit for data flows and that for packets that are sent to
the RADIUS server to the defaults.
Setting the maximum number of RADIUS request transmission attempts
Because RADIUS uses UDP packets to transfer data, the communication process is not reliable. RADIUS
uses a retransmission mechanism to improve the reliability. If a NAS sends a RADIUS request to a