28
Step Command
Remarks
number of real-time
accounting attempts.
5.
(Optional.) Enable buffering
of RADIUS stop-accounting
requests to which no
responses have been
received.
stop-accounting-buffer enable
By default, the buffering
feature is enabled.
6.
(Optional.) Set the maximum
number of transmission
attempts for individual
RADIUS stop-accounting
requests.
retry stop-accounting retries
The default setting is 500.
Specifying the shared keys for secure RADIUS communication
The RADIUS client and server use the MD5 algorithm and shared keys to generate the Authenticator
value for packet authentication and user password encryption. The client and server must use the
same key for each type of communication.
A key configured in this task is for all servers of the same type (accounting or authentication) in the
scheme. The key has a lower priority than a key configured individually for a RADIUS server.
To specify a shared key for secure RADIUS communication:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter RADIUS scheme
view.
radius scheme
radius-scheme-name
N/A
3.
Specify a shared key for
secure RADIUS
communication.
key
{
accounting
|
authentication
} {
cipher
|
simple
}
string
By default, no shared key is
specified for secure RADIUS
communication.
The shared key configured on the
device must be the same as the
shared key configured on the
RADIUS server.
Specifying an MPLS L3VPN instance for the scheme
The VPN instance specified for a RADIUS scheme applies to all authentication and accounting
servers in that scheme. If a VPN instance is also configured for an individual RADIUS server, the
VPN instance specified for the RADIUS scheme does not take effect on that server.
To specify a VPN instance for a scheme:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter RADIUS scheme view.
radius scheme
radius-scheme-name
N/A
3.
Specify a VPN instance for the
RADIUS scheme.
vpn-instance vpn-instance-name
By default, a RADIUS
scheme belongs to the public
network.
Setting the username format and traffic statistics units
A username is in the
userid
@
isp-name
format, where the
isp-name
argument represents the user's
ISP domain name. By default, the ISP domain name is included in a username. However, older
Содержание FlexFabric 5940 SERIES
Страница 251: ...238 ...