54
DAE defines the following types of packets:
•
Disconnect Messages (DMs)
—The DAE client sends DM requests to the DAE server to log off
specific online users.
•
Change of Authorization Messages (CoA Messages)
—The DAE client sends CoA requests
to the DAE server to change the authorization information of specific online users or shut down
or reboot the users' access ports.
To configure the RADIUS DAE server feature:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enable the RADIUS DAE
server feature and enter
RADIUS DAE server view.
radius dynamic-author server
By default, the RADIUS DAE
server feature is disabled.
3.
Specify a RADIUS DAE
client.
client
{
ip ipv4-address
|
ipv6
ipv6-address
} [
key
{
cipher
|
simple
}
string
|
vpn-instance
vpn-instance-name
] *
By default, no RADIUS DAE clients
are specified.
4.
Specify the RADIUS DAE
server port.
port
port-number
By default, the RADIUS DAE
server port is 3799.
Changing the DSCP priority for RADIUS packets
The DSCP priority in the ToS field determines the transmission priority of RADIUS packets. A larger
value represents a higher priority.
To change the DSCP priority for RADIUS packets:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Change the DSCP priority
for RADIUS packets.
radius
[
ipv6
]
dscp
dscp-value
By default, the DSCP priority is 0
for RADIUS packets.
Configuring the RADIUS attribute translation
feature
The RADIUS attribute translation feature enables the device to work correctly with the RADIUS
servers of different vendors that support RADIUS attributes incompatible with the device.
RADIUS attribute translation has the following implementations:
•
Attribute
conversion
—Converts source RADIUS attributes into destination RADIUS attributes
based on RADIUS attribute conversion rules.
•
Attribute
rejection
—Rejects RADIUS attributes based on RADIUS attribute rejection rules.
When the RADIUS attribute translation feature is enabled, the device processes RADIUS packets as
follows:
•
For the sent RADIUS packets:
{
Deletes the rejected attributes from the packets.
{
Uses the destination RADIUS attributes to replace the attributes that match RADIUS
attribute conversion rules in the packets.
Содержание FlexFabric 5940 SERIES
Страница 251: ...238 ...