Operation Manual - Security
Quidway S3000 Series Ethernet Switches
Chapter 2 AAA and RADIUS Protocol Configuration
2-10
end and give response.
You can use the following commands to set the encryption key for RADIUS packets.
Perform the following configurations in RADIUS server group view.
Table 2-9
Set RADIUS packet encryption key
Operation
Command
Set RADIUS authentication/authorization packet encryption key
key
authentication
string
Restore the default RADIUS authentication/authorization packet
encryption key.
undo key
authentication
Set RADIUS accounting packet key
key
accounting
string
Restore the default RADIUS accounting packet key
undo key
accounting
By default, the keys of RADIUS authentication/authorization and accounting packets
are all “huawei”.
2.3.4 Set Response Timeout Timer of RADIUS Server
After RADIUS (authentication/authorization or accounting) request packet has been
transmitted for a period of time, if NAS has not received the response from RADIUS
server, it has to retransmit the request to guarantee RADIUS service for the user.
You can use the following command to set response timeout timer of RADIUS server.
Perform the following configurations in RADIUS server group view.
Table 2-10
Set response timeout timer of RADIUS server
Operation
Command
Set response timeout timer of RADIUS server
timer
second
Restore the response timeout timer of RADIUS server to
default value
undo timer
By default, timeout timer of RADIUS server is 3 seconds.
2.3.5 Set Retransmission Times of RADIUS Request Packet
Since RADIUS protocol uses UDP packet to carry the data, the communication process
is not reliable. If the RADIUS server has not responded NAS before timeout, NAS has
to retransmit RADIUS request packet. If it transmits more than the specified
retry-times
,
NAS considers the communication with the primary and secondary RADIUS servers
has been disconnected.