27
Step Command
Remarks
ipv6-address
} [
port-number
|
key
{
cipher
|
simple
}
string
|
test-profile
profile-name
|
vpn-instance
vpn-instance-name
|
weight
weight-value
] *
The
weight
keyword takes effect
only when the RADIUS server load
sharing feature is enabled for the
RADIUS scheme.
Specifying the RADIUS accounting servers and the relevant parameters
You can specify one primary accounting server and a maximum of 16 secondary accounting servers
for a RADIUS scheme. Secondary servers provide AAA services when the primary server becomes
unavailable. The device searches for an active server in the order the secondary servers are
configured.
If redundancy is not required, specify only the primary server. A RADIUS accounting server can
function as the primary accounting server for one scheme and a secondary accounting server for
another scheme at the same time.
When RADIUS server load sharing is enabled, the device distributes the workload over all servers
without considering the primary and secondary server roles. The device checks the weight value and
number of currently served users for each active server, and then determines the most appropriate
server in performance to receive an accounting request.
When the maximum number of real-time accounting attempts is reached, the device disconnects
users who have no accounting responses.
The device sends RADIUS stop-accounting requests when it receives connection teardown requests
from hosts or connection teardown commands from an administrator. However, the device might fail
to receive a response for a stop-accounting request in a single transmission. Enable the device to
buffer RADIUS stop-accounting requests that have not received responses from the accounting
server. The device will resend the requests until responses are received.
To limit the transmission times, set a maximum number of transmission attempts that can be made
for individual RADIUS stop-accounting requests. When the maximum attempts are made for a
request, the device discards the buffered request.
RADIUS does not support accounting for FTP, SFTP, and SCP users.
To specify RADIUS accounting servers and the relevant parameters for a RADIUS scheme:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter RADIUS scheme view.
radius scheme
radius-scheme-name
N/A
3.
Specify RADIUS accounting
servers.
•
Specify the primary RADIUS
accounting server:
primary accounting
{
ipv4-address
|
ipv6
ipv6-address
} [
port-number
|
key
{
cipher
|
simple
}
string
|
vpn-instance
vpn-instance-name
|
weight
weight-value
] *
•
Specify a secondary RADIUS
accounting server:
secondary accounting
{
ipv4-address
|
ipv6
ipv6-address
} [
port-number
|
key
{
cipher
|
simple
}
string
|
vpn-instance
vpn-instance-name
|
weight
weight-value
] *
By default, no accounting
servers are specified.
Two accounting servers in a
scheme, primary or
secondary, cannot have the
same combination of IP
address, port number, and
VPN instance.
The
weight
keyword takes
effect only when the RADIUS
server load sharing feature is
enabled for the RADIUS
scheme.
4.
(Optional.) Set the maximum
retry realtime-accounting
retries
The default setting is 5.
Содержание FlexFabric 5940 SERIES
Страница 251: ...238 ...