HP 6125G HP 6125G & 6125G/XG Blade Switches Security Command Reference - Page 69

secondary authentication (RADIUS scheme view

Page 69 highlights

Related commands: key, state, and vpn-instance (RADIUS scheme view). Examples # For RADIUS scheme radius1, set the IP address of the secondary accounting server to 10.110.1.1, the UDP port to 1813, and the shared key to $c$3$NMCbVjyIutaV6csCOGp4zsKRTlg2eT3B in cipher text. system-view [Sysname] radius scheme radius1 [Sysname-radius-radius1] secondary accounting 10.110.1.1 1813 key cipher $c$3$NMCbVjyIutaV6csCOGp4zsKRTlg2eT3B # For RADIUS scheme radius2, specify two secondary accounting servers with the server IP addresses of 10.110.1.1 and 10.110.1.2 and the UDP port number of 1813. Set the shared keys to hello in plain text. system-view [Sysname] radius scheme radius2 [Sysname-radius-radius2] secondary accounting 10.110.1.1 1813 key hello [Sysname-radius-radius2] secondary accounting 10.110.1.2 1813 key hello secondary authentication (RADIUS scheme view) Syntax secondary authentication { ipv4-address | ipv6 ipv6-address } [ port-number | key [ cipher | simple ] key | probe username name [ interval interval ] | vpn-instance vpn-instance-name ] * View undo secondary authentication [ ipv4-address | ipv6 ipv6-address ] RADIUS scheme view Default level 2: System level Parameters ipv4-address: Specifies the IPv4 address of the secondary authentication/authorization server, in dotted decimal notation. ipv6 ipv6-address: Specifies the IPv6 address of the secondary authentication/authorization server. port-number: Specifies the service port number of the secondary RADIUS authentication/authorization server, which is a UDP port number in the range of 1 to 65535 and defaults to 1812. key [ cipher | simple ] key: Sets the shared key for secure communication with the secondary RADIUS authentication/authorization server. • cipher key: Sets a ciphertext shared key, which is a case-sensitive ciphertext string of 1 to 117 characters. • simple key: Sets a plaintext shared key, which is a case-sensitive string of 1 to 64 characters. • If neither cipher nor simple is specified, you set a plaintext shared key string. probe username: Enables the switch to detect the status of the secondary RADIUS authentication/authorization server. username name: Specifies the username in the authentication request that is used to detect the status of the secondary RADIUS authentication/authorization server. interval interval: Specifies the interval between two server status detections. The value ranges from 1 to 3600 and defaults to 60, in minutes. 60

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291

60
Related commands:
key
,
state
, and
vpn-instance
(RADIUS scheme view).
Examples
# For RADIUS scheme
radius1
, set the IP address of the secondary accounting server to 10.110.1.1, the
UDP port to 1813, and the shared key to
$c$3$NMCbVjyIutaV6csCOGp4zsKRTlg2eT3B
in cipher text.
<Sysname> system-view
[Sysname] radius scheme radius1
[Sysname-radius-radius1] secondary accounting 10.110.1.1 1813 key cipher
$c$3$NMCbVjyIutaV6csCOGp4zsKRTlg2eT3B
# For RADIUS scheme
radius2,
specify two secondary accounting servers with the server IP addresses of
10.110.1.1 and 10.110.1.2 and the UDP port number of 1813. Set the shared keys to
hello
in plain text.
<Sysname> system-view
[Sysname] radius scheme radius2
[Sysname-radius-radius2] secondary accounting 10.110.1.1 1813 key hello
[Sysname-radius-radius2] secondary accounting 10.110.1.2 1813 key hello
secondary authentication (RADIUS scheme view)
Syntax
secondary authentication
{
ipv4-address
|
ipv6
ipv6-address
} [
port-number
|
key
[
cipher
|
simple
]
key
|
probe username
name
[
interval
interval
]
|
vpn-instance
vpn-instance-name
] *
undo secondary authentication
[
ipv4-address
|
ipv6
ipv6-address
]
View
RADIUS scheme view
Default level
2: System level
Parameters
ipv4-address
: Specifies the IPv4 address of the secondary authentication/authorization server, in dotted
decimal notation.
ipv6
ipv6-address
: Specifies the IPv6 address of the secondary authentication/authorization server.
port-number
: Specifies the service port number of the secondary RADIUS authentication/authorization
server, which is a UDP port number in the range of 1 to 65535 and defaults to 1812.
key
[
cipher
|
simple
]
key
: Sets the shared key for secure communication with the secondary RADIUS
authentication/authorization server.
cipher
key
: Sets a ciphertext shared key, which is a case-sensitive ciphertext string of 1 to 117
characters.
simple
key
: Sets a plaintext shared key, which is a case-sensitive string of 1 to 64 characters.
If neither
cipher
nor
simple
is specified, you set a plaintext shared key string.
probe
username
: Enables the switch to detect the status of the secondary RADIUS
authentication/authorization server.
username
name
: Specifies the username in the authentication request that is used to detect the status of
the secondary RADIUS authentication/authorization server.
interval
interval
: Specifies the interval between two server status detections. The value ranges from 1 to
3600 and defaults to 60, in minutes.