HP 6125G HP 6125G & 6125G/XG Blade Switches Security Configuration Gui - Page 47

Setting timers for controlling communication with HWTACACS servers

Page 47 highlights

Step 3. Specify a source IP address for outgoing HWTACACS packets. Command nas-ip ip-address Remarks By default, the IP address of the outbound interface is used as the source IP address. Setting timers for controlling communication with HWTACACS servers The switch uses the following timers to control the communication with an HWTACACS server: • Server response timeout timer (response-timeout)-Defines the HWTACACS request retransmission interval. After sending an HWTACACS request (authentication, authorization, or accounting request), the switch starts this timer. If the switch receives no response from the server before this timer expires, it resends the request. • Server quiet timer (quiet)-Defines the duration to keep an unreachable server in blocked state. If a server is not reachable, the switch changes the server's status to blocked, starts this timer for the server, and tries to communicate with another server in active state. After this timer expires, the switch changes the status of the server back to active. • Real-time accounting timer (realtime-accounting)-Defines the interval at which the switch sends real-time accounting updates to the HWTACACS accounting server for online users. To implement real-time accounting, the switch must send real-time accounting packets to the accounting server for online users periodically. To set timers for controlling communication with HWTACACS servers: Step 1. Enter system view. 2. Enter HWTACACS scheme view. 3. Set the HWTACACS server response timeout timer. 4. Set the quiet timer for the primary server. 5. Set the real-time accounting interval. Command system-view hwtacacs scheme hwtacacs-scheme-name timer response-timeout seconds timer quiet minutes timer realtime-accounting minutes Remarks N/A N/A Optional. The default HWTACACS server response timeout timer is 5 seconds. Optional. The default quiet timer for the primary server is 5 minutes. Optional. The default real-time accounting interval is 12 minutes. NOTE: Consider the performance of the NAS and the HWTACACS server when you set the real-time accounting interval. A shorter interval requires higher performance. A shorter interval requires higher performance. Displaying and maintaining HWTACACS 37

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285

37
Step
Command
Remarks
3.
Specify a source IP address
for outgoing HWTACACS
packets.
nas-ip
ip-address
By default, the IP address of the
outbound interface is used as the
source IP address.
Setting timers for controlling communication with HWTACACS servers
The switch uses the following timers to control the communication with an HWTACACS server:
Server response timeout timer
(
response-timeout
)—Defines the HWTACACS request
retransmission interval. After sending an HWTACACS request (authentication, authorization, or
accounting request), the switch starts this timer. If the switch receives no response from the server
before this timer expires, it resends the request.
Server quiet timer
(
quiet
)—Defines the duration to keep an unreachable server in blocked state. If
a server is not reachable, the switch changes the server’s status to blocked, starts this timer for the
server, and tries to communicate with another server in active state. After this timer expires, the
switch changes the status of the server back to active.
Real-time accounting timer
(
realtime-accounting
)—Defines the interval at which the switch sends
real-time accounting updates to the HWTACACS accounting server for online users. To implement
real-time accounting, the switch must send real-time accounting packets to the accounting server for
online users periodically.
To set timers for controlling communication with HWTACACS servers:
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter HWTACACS scheme
view.
hwtacacs scheme
hwtacacs-scheme-name
N/A
3.
Set the HWTACACS server
response timeout timer.
timer response-timeout
seconds
Optional.
The default HWTACACS server
response timeout timer is 5
seconds.
4.
Set the quiet timer for the
primary server.
timer quiet
minutes
Optional.
The default quiet timer for the
primary server is 5 minutes.
5.
Set the real-time accounting
interval.
timer realtime-accounting
minutes
Optional.
The default real-time accounting
interval is 12 minutes.
NOTE:
Consider the performance of the NAS and the HWTACACS server when you set the real-time accounting
interval. A shorter interval requires higher performance. A shorter interval requires higher performance.
Displaying and maintaining HWTACACS