33
client rather than adjusting the RADIUS packet transmission attempts and server response
timeout timer. Typically, the next attempt will succeed, because the device has blocked the
unreachable servers to shorten the time to find a reachable server.
•
Make sure the server quiet timer is set correctly. A timer that is too short might result in frequent
authentication or accounting failures. This is because the device will continue to attempt to
communicate with an unreachable server that is in active state. A timer that is too long might
temporarily block a reachable server that has recovered from a failure. This is because the
server will remain in blocked state until the timer expires.
•
A short real-time accounting interval helps improve accounting precision but requires many
system resources. When there are 1000 or more users, set the interval to 15 minutes or longer.
To set RADIUS timers:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter RADIUS scheme view.
radius scheme
radius-scheme-name
N/A
3.
Set the RADIUS server
response timeout timer.
timer response-timeout
seconds
The default setting is 3 seconds.
4.
Set the quiet timer for the
servers.
timer quiet
minutes
The default setting is 5 minutes.
5.
Set the real-time accounting
timer.
timer realtime-accounting
interval
[
second
]
The default setting is 12 minutes.
Configuring the RADIUS accounting-on feature
When the accounting-on feature is enabled, the device automatically sends an accounting-on packet
to the RADIUS server after the entire device reboots. Upon receiving the accounting-on packet, the
RADIUS server logs out all online users so they can log in again through the device. Without this
feature, users cannot log in again after the reboot, because the RADIUS server considers them to
come online.
You can configure the interval for which the device waits to resend the accounting-on packet and the
maximum number of retries.
The extended accounting-on feature enhances the accounting-on feature in a distributed
architecture. For the extended accounting-on feature to take effect, the RADIUS server must run on
IMC and the accounting-on feature must be enabled.
The extended accounting-on feature is applicable to LAN users. The user data is saved to the IRF
member devices through which the users access the system. When the extended accounting-on
feature is enabled, the system automatically sends an accounting-on packet to the RADIUS server
after a member device reboot. The packet contains the member device identifier. Upon receiving the
accounting-on packet, the RADIUS server logs out all online users who access the system through
the member device.
To configure the accounting-on feature for a RADIUS scheme:
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter RADIUS scheme view.
radius scheme
radius-scheme-name
N/A
3.
Enable accounting-on.
accounting-on enable
[
interval
interval
|
send
send-times
] *
By default, the accounting-on
feature is disabled.
4.
(Optional.) Enable extended
accounting-on.
accounting-on extended
By default, extended
accounting-on is disabled.
Содержание FlexFabric 5940 SERIES
Страница 251: ...238 ...