
1.7 Configuration Examples
This section provides several AAA configuration examples. The configuration examples explain
networking requirements, configuration notes, and configuration roadmap.
1.7.1 Example for Configuring RADIUS Authentication,
Authorization, and Accounting
Networking Requirements
, users access the network through RouterA and belong to the domain
huawei
. RouterB functions as the network access server of the destination network. Request
packets from users need to traverse the network where RouterA and RouterB are located to reach
the authentication server. Users can access the destination network through RouterB after being
authenticated. The remote authentication configuration on RouterB is as follows:
l
The RADIUS server performs authentication and accounting for access users.
l
The RADIUS server at 129.7.66.66/24 functions as the primary authentication and
accounting server. The RADIUS server at 129.7.66.67/24 functions as the secondary
authentication and accounting server. The default authentication port and accounting port
are 1812 and 1813.
Figure 1-4
Networking diagram of RADIUS authentication and accounting
Router A
Router B
Destination
network
Domain Huawei
Network
129.7.66.66/24
129.7.66.67/24
Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
1 AAA Configuration
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
28