HP 6125G HP 6125G & 6125G/XG Blade Switches Security Configuration Gui - Page 30

Configuring RADIUS schemes, RADIUS scheme configuration task list, Creating a RADIUS scheme

Page 30 highlights

Configuring RADIUS schemes A RADIUS scheme specifies the RADIUS servers that the switch can cooperate with and defines a set of parameters that the switch uses to exchange information with the RADIUS servers. There may be authentication/authorization servers and accounting servers, or primary servers and secondary servers. The parameters include the IP addresses of the servers, the shared keys, and the RADIUS server type. RADIUS scheme configuration task list Task Creating a RADIUS scheme Specifying the RADIUS authentication/authorization servers Specifying the RADIUS accounting servers and the relevant parameters Specifying the shared keys for secure RADIUS communication Specifying the VPN to which the servers belong Setting the username format and traffic statistics units Setting the supported RADIUS server type Setting the maximum number of RADIUS request transmission attempts Setting the status of RADIUS servers Specifying the source IP address for outgoing RADIUS packets Setting timers for controlling communication with RADIUS servers Configuring RADIUS accounting-on Configuring the IP address of the security policy server Configuring interpretation of RADIUS class attribute as CAR parameters Enabling the trap function for RADIUS Enabling the RADIUS listening port of the RADIUS client Setting the DSCP value for RADIUS protocol packets Displaying and maintaining RADIUS Remarks Required Required Optional Optional Optional Optional Optional Optional Optional Optional Optional Optional Optional Optional Optional Optional Optional Optional Creating a RADIUS scheme Before performing other RADIUS configurations, follow these steps to create a RADIUS scheme and enter RADIUS scheme view: Step Command 1. Enter system view. system-view 2. Create a RADIUS scheme and radius scheme enter RADIUS scheme view. radius-scheme-name Remarks N/A No RADIUS scheme exists by default. NOTE: A RADIUS scheme can be referenced by multiple ISP domains at the same time. 20

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285

20
Configuring RADIUS schemes
A RADIUS scheme specifies the RADIUS servers that the switch can cooperate with and defines a set of
parameters that the switch uses to exchange information with the RADIUS servers. There may be
authentication/authorization servers and accounting servers, or primary servers and secondary servers.
The parameters include the IP addresses of the servers, the shared keys, and the RADIUS server type.
RADIUS scheme configuration task list
Task
Remarks
Creating a RADIUS scheme
Required
Specifying the RADIUS authentication/authorization servers
Required
Specifying the RADIUS accounting servers and the relevant parameters
Optional
Specifying the shared keys for secure RADIUS communication
Optional
Specifying the VPN to which the servers belong
Optional
Setting the username format and traffic statistics units
Optional
Setting the supported RADIUS server type
Optional
Setting the maximum number of RADIUS request transmission attempts
Optional
Setting the status of RADIUS servers
Optional
Specifying the source IP address for outgoing RADIUS packets
Optional
Setting timers for controlling communication with RADIUS servers
Optional
Configuring RADIUS accounting-on
Optional
Configuring the IP address of the security policy server
Optional
Configuring interpretation of RADIUS class attribute as CAR parameters
Optional
Enabling the trap function for RADIUS
Optional
Enabling the RADIUS listening port of the RADIUS client
Optional
Setting the DSCP value for RADIUS protocol packets
Optional
Displaying and maintaining RADIUS
Optional
Creating a RADIUS scheme
Before performing other RADIUS configurations, follow these steps to create a RADIUS scheme and enter
RADIUS scheme view:
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Create a RADIUS scheme and
enter RADIUS scheme view.
radius scheme
radius-scheme-name
No RADIUS scheme exists by
default.
NOTE:
A RADIUS scheme can be referenced by multiple ISP domains at the same time.