Operation Manual - Security
Quidway S3000 Series Ethernet Switches
Chapter 2 AAA and RADIUS Protocol Configuration
2-8
2.3.1 Create/Delete a RADIUS server Group
As mentioned above, RADIUS protocol configurations are performed on the per
RADIUS server group basis. Therefore, before performing other RADIUS protocol
configurations, it is compulsory to create the RADIUS server group and enter its view to
set its IP address.
You can use the following commands to create/delete a RADIUS server group.
Perform the following configurations in system view.
Table 2-7
Create/Delete a RADIUS server group
Operation
Command
Create a RADIUS server group and enter its view
radius scheme
radius-server-name
Delete a RADIUS server group
undo radius scheme
radius-server-name
Several ISP domains can use a RADIUS server group at the same time.
By default, the system has a RADIUS server group named “default” whose attributes
are all default values. The default attribute values will be introduced in the following
text.
2.3.2 Set IP Address and Port Number of RADIUS Server
After creating a RADIUS server group, you are supposed to set IP addresses and UDP
port numbers for the RADIUS servers, including primary/second
authentication/authorization servers and accounting servers. So you can configure up
to 4 groups of IP addresses and UDP port numbers. However, at least you have to set
one group of IP address and UDP port number for each pair of primary/second servers
to ensure the normal AAA operation.
You can use the following commands to configure the IP address and port number for
RADIUS servers.
Perform the following configurations in RADIUS server group view.
Table 2-8
Set IP Address and Port Number of RADIUS Server
Operation
Command
Set IP address and port number of primary RADIUS
authentication/authorization server.
primary authentication
ip-address
[
port-number
]
Restore IP address and port number of primary RADIUS
authentication/authorization or server to the default
values.
undo primary authentication
Set IP address and port number of primary RADIUS
accounting server.
primary
accounting
ip-address
[
port-number
]