HP StorageWorks 2/16V HP StorageWorks Fabric OS 5.X Procedures User Guide (AA- - Page 51

Changing a RADIUS server configuration, Enabling or disabling RADIUS service

Page 51 highlights

Adding a RADIUS server to the switch configuration 1. Connect to the switch and log in as admin. 2. Issue the following command: switch:admin> aaaConfig --add server [-p port] [-s secret] [-t timeout] [-a pap | chap] where: server Is either a server name or an IP address. Avoid duplicating server listings (that is, listing the same server once by name and again by IP address). Up to five servers can be added to the configuration. -p port Is an optional argument; enter a server port. The default is port 1812. -s secret Is an optional argument; enter a shared secret. The default is sharedsecret. Secrets can be 8 to 40 alphanumeric characters. Make sure that the secret matches that configured on the server. -t timeout Is an optional argument; enter the length of time (in seconds) that the server has to respond before the next server is contacted. The default is 3 seconds. Timeout values can range from 1 to 30 seconds. -a[pap|chap] Specifies PAP or CHAP as the authentication protocol. Enabling or disabling RADIUS service 1. Connect to the switch and log in as admin. 2. Issue the following command: switch:admin> aaaConfig --radius on | off Specifying on enables the service; specifying off disables it. At least one RADIUS server must be configured before you can enable RADIUS service. If no RADIUS configuration exists, turning it on triggers an error message. When the command succeeds, the event log indicates that the configuration is enabled or disabled. Deleting a RADIUS server from the configuration 1. Connect to the switch and log in as admin. 2. Issue the following command: switch:admin> aaaConfig --remove server | all where server is a list of servers by either name or IP address. Enter either the name or IP address of the server to be removed. 3. At the prompt, enter y to complete the command. When the command succeeds, the event log indicates that the server is removed. Changing a RADIUS server configuration 1. Connect to the switch and log in as admin. 2. Issue the following command: switch:admin> aaaConfig --change server [-p port] [-s secret] [-t timeout] [-a pap | chap] where: server Is a list of servers by either name or IP address. Enter either the name or IP address of the server to be changed. Fabric OS 5.x administrator guide 51

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248

Fabric OS 5.x administrator guide
51
Adding a RADIUS server to the switch configuration
1.
Connect to the switch and log in as admin.
2.
Issue the following command:
switch:admin> aaaConfig --add
server
[-p
port
] [-s
secret
] [-t
timeout
]
[-a pap | chap]
Enabling or disabling RADIUS service
1.
Connect to the switch and log in as admin.
2.
Issue the following command:
switch:admin> aaaConfig --radius on | off
Specifying
on
enables the service; specifying
off
disables it.
At least one RADIUS server must be configured before you can enable RADIUS service.
If no RADIUS configuration exists, turning it on triggers an error message. When the command succeeds,
the event log indicates that the configuration is enabled or disabled.
Deleting a RADIUS server from the configuration
1.
Connect to the switch and log in as admin.
2.
Issue the following command:
switch:admin> aaaConfig --remove
server
| all
where
server
is a list of servers by either name or IP address. Enter either the name or IP address of
the server to be removed.
3.
At the prompt, enter
y
to complete the command.
When the command succeeds, the event log indicates that the server is removed.
Changing a RADIUS server configuration
1.
Connect to the switch and log in as admin.
2.
Issue the following command:
switch:admin> aaaConfig --change
server
[-p
port
] [-s
secret
] [-t
timeout
]
[-a pap | chap]
where:
server
Is either a server name or an IP address. Avoid duplicating server listings
(that is, listing the same server once by name and again by IP address).
Up to five servers can be added to the configuration.
-p
port
Is an optional argument; enter a server port. The default is port
1812
.
-s
secret
Is an optional argument; enter a shared secret. The default is
sharedsecret
. Secrets can be 8 to 40 alphanumeric characters. Make
sure that the secret matches that configured on the server.
-t
timeout
Is an optional argument; enter the length of time (in seconds) that the
server has to respond before the next server is contacted. The default is 3
seconds. Timeout values can range from 1 to 30 seconds.
-a[pap|chap]
Specifies
PAP
or
CHAP
as the authentication protocol.
where:
server
Is a list of servers by either name or IP address. Enter either the name or IP
address of the server to be changed.