HP 6125G HP 6125G & 6125G/XG Blade Switches Security Command Reference - Page 66

retry realtime-accounting, timer response-timeout

Page 66 highlights

[Sysname-radius-radius1] retry 5 retry realtime-accounting Syntax retry realtime-accounting retry-times View undo retry realtime-accounting RADIUS scheme view Default level 2: System level Parameters retry-times: Maximum number of accounting attempts, in the range of 1 to 255. Description Use retry realtime-accounting to set the maximum number of accounting attempts. Use undo retry realtime-accounting to restore the default. By default, the maximum number of accounting attempts is 5. A RADIUS server usually checks whether a user is online by using a timeout timer. If it receives no real-time accounting request for a user in the timeout period from the NAS, it considers that there may be link or switch failures and stops accounting for the user. This may happen when some unexpected failure occurs. To cooperate with this feature of the RADIUS server, the NAS must keep pace with the server in disconnecting the user. The maximum number of accounting attempts, together with some other parameters, enables the NAS to promptly disconnect the user. The maximum number of accounting attempts, together with some other parameters, controls how the NAS sends accounting request packets. Suppose that the RADIUS server response timeout period is three seconds (set with the timer response-timeout command), the maximum number of RADIUS packet transmission attempts is three (set with the retry command), the real-time accounting interval is 12 minutes (set with the timer realtime-accounting command), and the maximum number of accounting attempts is five (set with the retry realtime-accounting command). In this case, the switch generates an accounting request every 12 minutes, and retransmits the request if it sends the request but receives no response within three seconds. If the switch receives no response after transmitting the request three times, it considers the accounting attempt a failure, and makes another accounting attempt. If five consecutive accounting attempts fail, the switch cuts the user connection. Related commands: retry, timer response-timeout, and timer realtime-accounting. Examples # Set the maximum number of accounting attempts to 10 for RADIUS scheme radius1. system-view [Sysname] radius scheme radius1 [Sysname-radius-radius1] retry realtime-accounting 10 57

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291

57
[Sysname-radius-radius1] retry 5
retry realtime-accounting
Syntax
retry realtime-accounting
retry-times
undo retry realtime-accounting
View
RADIUS scheme view
Default level
2: System level
Parameters
retry-times
: Maximum number of accounting attempts, in the range of 1 to 255.
Description
Use
retry realtime-accounting
to set the maximum number of accounting attempts.
Use
undo retry realtime-accounting
to restore the default.
By default, the maximum number of accounting attempts is 5.
A RADIUS server usually checks whether a user is online by using a timeout timer. If it receives no
real-time accounting request for a user in the timeout period from the NAS, it considers that there may be
link or switch failures and stops accounting for the user. This may happen when some unexpected failure
occurs. To cooperate with this feature of the RADIUS server, the NAS must keep pace with the server in
disconnecting the user. The maximum number of accounting attempts, together with some other
parameters, enables the NAS to promptly disconnect the user.
The maximum number of accounting attempts, together with some other parameters, controls how the
NAS sends accounting request packets.
Suppose that the RADIUS server response timeout period is three seconds (set with the
timer
response-timeout
command), the maximum number of RADIUS packet transmission attempts is three (set
with the
retry
command), the real-time accounting interval is 12 minutes (set with the
timer
realtime-accounting
command), and the maximum number of accounting attempts is five (set with the
retry realtime-accounting
command). In this case, the switch generates an accounting request every 12
minutes, and retransmits the request if it sends the request but receives no response within three seconds.
If the switch receives no response after transmitting the request three times, it considers the accounting
attempt a failure, and makes another accounting attempt. If five consecutive accounting attempts fail, the
switch cuts the user connection.
Related commands:
retry
,
timer response-timeout
, and
timer realtime-accounting
.
Examples
# Set the maximum number of accounting attempts to 10 for RADIUS scheme
radius1
.
<Sysname> system-view
[Sysname] radius scheme radius1
[Sysname-radius-radius1] retry realtime-accounting 10