21
Configuring RADIUS schemes
A RADIUS scheme specifies the RADIUS servers that the router can cooperate with and defines a set of
parameters that the router uses to exchange information with the RADIUS servers. There may be
authentication/authorization servers and accounting servers, or primary servers and secondary servers.
The parameters mainly include the IP addresses of the servers, the shared keys, and the RADIUS server
type.
RADIUS scheme configuration task list
Task Remarks
Required
Specifying the RADIUS authentication/authorization servers
Required
Specifying the RADIUS accounting servers and the relevant parameters
Optional
Specifying the shared keys for authenticating RADIUS packets
Optional
Specifying the VPN to which the servers belongs
Optional
Setting the supported RADIUS server type
Optional
Setting the maximum number of RADIUS request transmission attempts
Optional
Setting the status of RADIUS servers
Optional
Setting the username format and traffic statistics units
Optional
Specifying the source IP address for outgoing RADIUS packets
Optional
Specifying a backup source IP address for outgoing RADIUS packets
Optional
Setting timers for controlling communication with RADIUS servers
Optional
Configuring RADIUS accounting-on
Optional
Configuring the IP address of the security policy server
Optional
Enabling the RADIUS offload feature
Optional
Configuring interpretation of RADIUS class attribute as CAR parameters
Optional
Enabling the trap function for RADIUS
Optional
Enabling the RADIUS listening port of the RADIUS client
Optional
Displaying and maintaining RADIUS
Optional
Creating a RADIUS scheme
Before performing other RADIUS configurations, create a RADIUS scheme and enter RADIUS scheme
view:
To do…
Command…
Remarks
1.
Enter system view.
system-view
—
2.
Create a RADIUS scheme and
enter RADIUS scheme view.
radius scheme
radius-scheme-
name
Required
No RADIUS scheme by default