HP 6125G HP 6125G & 6125G/XG Blade Switches Security Command Reference - Page 73

state secondary

Page 73 highlights

block: Specifies the blocked state, the out-of-service state. Description Use state primary to set the status of a primary RADIUS server. By default, the primary RADIUS server specified for a RADIUS scheme is in active state. During an authentication or accounting process, the switch first tries to communicate with the primary server if the primary server is in active state. If the primary server is unavailable, the switch changes the status of the primary server to blocked, starts a quiet timer for the server, and then tries to communicate with a secondary server in active state (a secondary RADIUS server configured earlier has a higher priority). When the quiet timer of the primary server times out, the status of the server changes to active automatically. If you set the status of the server to blocked before the quiet timer times out, the status of the server cannot change back to active automatically unless you set the status to active manually. When the primary server and secondary servers are both in blocked state, the switch communicates with the primary server. Related commands: display radius scheme and state secondary. Examples # Set the status of the primary server in RADIUS scheme radius1 to blocked. system-view [Sysname] radius scheme radius1 [Sysname-radius-radius1] state primary authentication block state secondary Syntax View state secondary { accounting | authentication } [ ip ipv4-address | ipv6 ipv6-address ] { active | block } RADIUS scheme view Default level 2: System level Parameters accounting: Sets the status of the secondary RADIUS accounting server. authentication: Sets the status of the secondary RADIUS authentication/authorization server. ip ipv4-address: Specifies the IPv4 address of the secondary RADIUS server. ipv6 ipv6-address: Specifies the IPv6 address of the secondary RADIUS server. active: Specifies the active state, the normal operation state. block: Specifies the blocked state, the out-of-service state. Description Use state secondary to set the status of a secondary RADIUS server. By default, every secondary RADIUS server specified in a RADIUS scheme is in active state. If no IP address is specified, this command changes the status of all configured secondary servers for authentication/authorization or accounting. 64

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291

64
block
: Specifies the blocked state, the out-of-service state.
Description
Use
state
primary
to set the status of a primary RADIUS server.
By default, the primary RADIUS server specified for a RADIUS scheme is in active state.
During an authentication or accounting process, the switch first tries to communicate with the primary
server if the primary server is in active state. If the primary server is unavailable, the switch changes the
status of the primary server to blocked, starts a quiet timer for the server, and then tries to communicate
with a secondary server in active state (a secondary RADIUS server configured earlier has a higher
priority). When the quiet timer of the primary server times out, the status of the server changes to active
automatically. If you set the status of the server to blocked before the quiet timer times out, the status of
the server cannot change back to active automatically unless you set the status to active manually.
When the primary server and secondary servers are both in blocked
state, the switch communicates with
the primary server.
Related commands:
display
radius scheme
and
state
secondary
.
Examples
# Set the status of the primary server in RADIUS scheme
radius1
to blocked.
<Sysname> system-view
[Sysname] radius scheme radius1
[Sysname-radius-radius1] state primary authentication block
state secondary
Syntax
state
secondary
{
accounting
|
authentication
} [
ip
ipv4-address
|
ipv6
ipv6-address
] {
active
|
block
}
View
RADIUS scheme view
Default level
2: System level
Parameters
accounting
: Sets the status of the secondary RADIUS accounting server.
authentication
: Sets the status of the secondary RADIUS authentication/authorization server.
ip
ipv4-address
: Specifies the IPv4 address of the secondary RADIUS server.
ipv6
ipv6-address
: Specifies the IPv6 address of the secondary RADIUS server.
active
: Specifies the active state, the normal operation state.
block
: Specifies the blocked state, the out-of-service state.
Description
Use
state
secondary
to set the status of a secondary RADIUS server.
By default, every secondary RADIUS server specified in a RADIUS scheme is in active state.
If no IP address is specified, this command changes the status of all configured secondary servers for
authentication/authorization or accounting.