HP 6125G HP 6125G & 6125G/XG Blade Switches Security Command Reference - Page 58

primary authentication (RADIUS scheme view

Page 58 highlights

primary authentication (RADIUS scheme view) Syntax primary authentication { ipv4-address | ipv6 ipv6-address } [ port-number | key [ cipher | simple ] key | probe username name [ interval interval ] | vpn-instance vpn-instance-name ] * View undo primary authentication RADIUS scheme view Default level 2: System level Parameters ipv4-address: Specifies the IPv4 address of the primary authentication/authorization server. ipv6 ipv6-address: Specifies the IPv6 address of the primary authentication/authorization server. port-number: Specifies the service port number of the primary RADIUS authentication/authorization server, which is a UDP port number in the range of 1 to 65535 and defaults to 1812. key [ cipher | simple ] key: Sets the shared key for secure communication with the primary RADIUS authentication/authorization server. • cipher key: Sets a ciphertext shared key, which is a case-sensitive ciphertext string of 1 to 117 characters. • simple key: Sets a plaintext shared key, which is a case-sensitive string of 1 to 64 characters. • If neither cipher nor simple is specified, you set a plaintext shared key string. probe username: Enables the switch to detect the status of the primary RADIUS authentication/authorization server. username name: Specifies the username in the authentication request that is used to detect the status of the primary RADIUS authentication/authorization server. interval interval: Specifies the interval between two server status detections. The value ranges from 1 to 3600 and defaults to 60, in minutes. vpn-instance vpn-instance-name: Specifies the MPLS L3VPN to which the primary RADIUS authentication/authorization server belongs, where vpn-instance-name is a case-sensitive string of 1 to 31 characters. If the server is on the public network, do not specify this option. Description Use primary authentication to specify the primary RADIUS authentication/authorization server. Use undo primary authentication to remove the configuration. By default, no primary RADIUS authentication/authorization server is specified. Make sure the port number and shared key settings of the primary RADIUS accounting server are the same as those configured on the server. The IP addresses of the authentication/authorization servers and those of the accounting servers must be of the same IP version. The IP addresses of the primary and secondary authentication/authorization servers must be different from each other and use the same IP version. Otherwise, the configuration fails. 49

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291

49
primary authentication (RADIUS scheme view)
Syntax
primary authentication
{
ipv4-address
|
ipv6
ipv6-address
} [
port-number
|
key
[
cipher
|
simple
]
key
|
probe username
name
[
interval
interval
] |
vpn-instance
vpn-instance-name
] *
undo primary authentication
View
RADIUS scheme view
Default level
2: System level
Parameters
ipv4-address
: Specifies the IPv4 address of the primary authentication/authorization server.
ipv6
ipv6-address
: Specifies the IPv6 address of the primary authentication/authorization server.
port-number
: Specifies the service port number of the primary RADIUS authentication/authorization
server, which is a UDP port number in the range of 1 to 65535 and defaults to 1812.
key
[
cipher
|
simple
]
key
: Sets the shared key for secure communication with the primary RADIUS
authentication/authorization server.
cipher
key
: Sets a ciphertext shared key, which is a case-sensitive ciphertext string of 1 to 117
characters.
simple
key
: Sets a plaintext shared key, which is a case-sensitive string of 1 to 64 characters.
If neither
cipher
nor
simple
is specified, you set a plaintext shared key string.
probe
username
:
Enables
the
switch
to
detect
the
status
of
the
primary
RADIUS
authentication/authorization server.
username
name
: Specifies the username in the authentication request that is used to detect the status of
the primary RADIUS authentication/authorization server.
interval
interval
: Specifies the interval between two server status detections. The value ranges from 1 to
3600 and defaults to 60, in minutes.
vpn-instance
vpn-instance-name
: Specifies the MPLS L3VPN to which the primary RADIUS
authentication/authorization server belongs, where
vpn-instance-name
is a case-sensitive string of 1 to
31 characters. If the server is on the public network, do not specify this option.
Description
Use
primary authentication
to specify the primary RADIUS authentication/authorization server.
Use
undo primary authentication
to remove the configuration.
By default, no primary RADIUS authentication/authorization server is specified.
Make sure the port number and shared key settings of the primary RADIUS accounting server are the
same as those configured on the server.
The IP addresses of the authentication/authorization servers and those of the accounting servers must be
of the same IP version.
The IP addresses of the primary and secondary authentication/authorization servers must be different
from each other and use the same IP version. Otherwise, the configuration fails.