Raisecom
ISCOM2600G-HI (A) Series Configuration Guide
10 Security
Raisecom Proprietary and Confidential
Copyright © Raisecom Technology Co., Ltd.
418
10.4.2 Preparing for configurations
Scenario
You can deploy the RADIUS server on the network to conduct authentication and accounting
to control users to access to the ISCOM2600G-HI series switch and network. The
ISCOM2600G-HI series switch can be used as agent of the RADIUS server, which authorizes
user to access according to feedback from RADIUS.
Prerequisite
N/A
10.4.3 Default configurations of RADIUS
Default configurations of RADIUS are as below.
Function
Default value
RADIUS accounting
Disable
IP address of the RADIUS server
0.0.0.0
Timeout of the RADIUS server
3s
IP address of the RADIUS accounting server
0.0.0.0
Port ID of the RADIUS authentication server
1812
Port ID of the RADIUS accounting server
1813
Shared key for communicating with the RADIUS accounting server
N/A
Processing policy for accounting failure
Online
Period for sending Account-Update packets
0
10.4.4 Configuring RADIUS authentication
Configure RADIUS authentication for the ISCOM2600G-HI series switch as below.
Step
Command
Description
1
Raisecom#radius [ backup ]
{
ipv4-address
|
ipv6-
address
} [ auth-port
port-
id
]
Assign the IP address and port ID for
RADIUS authentication server.
Configure the
backup
parameter to
assign the backup RADIUS
authentication server.
2
Raisecom#radius-key
string
Configure the shared key for RADIUS
authentication.
3
Raisecom#radius-encrypt-key
word
Configure the RADIUS authentication
server to encrypt data in cyphertext
mode.