HP 6125G HP 6125G & 6125G/XG Blade Switches Security Command Reference - Page 63

radius trap

Page 63 highlights

A RADIUS scheme can be referenced by more than one ISP domain at the same time. A RADIUS scheme referenced by ISP domains cannot be removed. Related commands: display radius scheme. Examples # Create a RADIUS scheme named radius1 and enter RADIUS scheme view. system-view [Sysname] radius scheme radius1 [Sysname-radius-radius1] radius trap Syntax radius trap { accounting-server-down | authentication-error-threshold | authentication-server-down } undo radius trap { accounting-server-down | authentication-error-threshold | authentication-server-down } View System view Default level 2: System level Parameters accounting-server-down: Sends traps when the reachability of the accounting server changes. authentication-error-threshold: Sends traps when the number of authentication failures exceed the specified threshold. The threshold is represented by the ratio of the number of failed request transmission attempts to the total number of transmission attempts. It ranges from 1 to 100 and defaults to 30. This threshold can only be configured through the MIB. authentication-server-down: Sends traps when the reachability of the authentication server changes. Description Use radius trap to enable the trap function for RADIUS. Use undo radius trap to disable the trap function for RADIUS. By default, the trap function is disabled for RADIUS. With the trap function for RADIUS, a NAS sends a trap message in the following cases: • The status of a RADIUS server changes. If a NAS sends a request but receives no response before the maximum number of attempts is exceeded, it places the server to blocked state and sends a trap message. If a NAS receives a response from a RADIUS server it considered unreachable, it considers that the RADIUS server is reachable again and also sends a trap message. • The ratio of the number of failed transmission attempts to the total number of authentication request transmission attempts reaches the threshold. Examples # Enable the switch to send traps in response to accounting server reachability changes. system-view [Sysname] radius trap accounting-server-down 54

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291

54
A RADIUS scheme can be referenced by more than one ISP domain at the same time.
A RADIUS scheme referenced by ISP domains cannot be removed.
Related commands:
display radius scheme
.
Examples
# Create a RADIUS scheme named
radius1
and enter RADIUS scheme view.
<Sysname> system-view
[Sysname] radius scheme radius1
[Sysname-radius-radius1]
radius trap
Syntax
radius trap
{
accounting-server-down
|
authentication-error-threshold
|
authentication-server-down
}
undo
radius
trap
{
accounting-server-down
|
authentication-error-threshold
|
authentication-server-down
}
View
System view
Default level
2: System level
Parameters
accounting-server-down
: Sends traps when the reachability of the accounting server changes.
authentication-error-threshold
: Sends traps when the number of authentication failures exceed the
specified threshold. The threshold is represented by the ratio of the number of failed request transmission
attempts to the total number of transmission attempts. It ranges from 1 to 100 and defaults to 30. This
threshold can only be configured through the MIB.
authentication-server-down
: Sends traps when the reachability of the authentication server changes.
Description
Use
radius trap
to enable the trap function for RADIUS.
Use
undo radius trap
to disable the trap function for RADIUS.
By default, the trap function is disabled for RADIUS.
With the trap function for RADIUS, a NAS sends a trap message in the following cases:
The status of a RADIUS server changes. If a NAS sends a request but receives no response before
the maximum number of attempts is exceeded, it places the server to blocked state and sends a trap
message. If a NAS receives a response from a RADIUS server it considered unreachable, it
considers that the RADIUS server is reachable again and also sends a trap message.
The ratio of the number of failed transmission attempts to the total number of authentication request
transmission attempts reaches the threshold.
Examples
# Enable the switch to send traps in response to accounting server reachability changes.
<Sysname> system-view
[Sysname] radius trap accounting-server-down