HP StorageWorks MSA 2/8 HP StorageWorks Fabric OS 3.X Document Addendum (AA-RW - Page 142

Setting Up the Switch, Enabling and Disabling RADIUS Service

Page 142 highlights

Fabric OS procedures user guide Setting Up the Switch The following procedures show how to use the aaaconfig command to set up a single switch for RADIUS service. You can also set up multiple switches simultaneously with the HP Fabric Manager optional software tool. To display the current RADIUS configuration, issue the command: aaaConfig "--show" If a configuration exists, its parameters are displayed. If RADIUS service is not configured, only the parameter heading line is displayed. Parameters are: Position The order in which servers are contacted to provide service Server The server names or IP addresses Port The server ports Secret The shared secrets Timeouts The length of time servers have to respond before the next server is contacted Authentication The type of authentication being used on servers To add a RADIUS server to the configuration, issue the command: aaaConfig "--add server [-p port] [-s secret] [-t timeout] [-a]-" where: server -p port -s secret -t timeout -a Is a server name or IP address. Avoid duplicating server listings (that is, listing the same server once by name and again by IP address). Up to five servers can be added to the configuration. Is an option; enter a server port. The default is port 1812. Is an option; enter a shared secret. The default is sharedsecret. Secrets can contain 8 to 40 alphanumeric characters. Is an option; enter the length of time (in seconds) the server has to respond before the next server is contacted. The default is 3 seconds. Timeout values can range from 1 to 30 seconds. Is an option; specify that the PAP protocol be used instead of the CHAP protocol for packets traveling between the switch and the server. Enabling and Disabling RADIUS Service: At least one RADIUS server must be configured before you can enable RADIUS service. To enable or disable RADIUS service, issue the command: aaaConfig "--radius on | off" Specifying on enables the service; specifying off disables it. If no RADIUS configuration exists, turning it on triggers an error message. When the command succeeds, an event is sent to the event log, indicating that the configuration is enabled or disabled. 142 Fabric OS 3.x Document Addendum

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250

Fabric OS procedures user guide
142
Fabric OS 3.x Document Addendum
Setting Up the Switch
The following procedures show how to use the
aaaconfig
command to set up a single
switch for RADIUS service. You can also set up multiple switches simultaneously with the HP
Fabric Manager optional software tool.
To display the current RADIUS configuration, issue the command:
aaaConfig ”--show“
If a configuration exists, its parameters are displayed. If RADIUS service is not configured,
only the parameter heading line is displayed. Parameters are:
To add a RADIUS server to the configuration, issue the command:
aaaConfig ”--add
server
[-p
port
] [-s
secret
] [-t
timeout
] [-a]–“
Enabling and Disabling RADIUS Service:
At least one RADIUS server must be configured before you can enable RADIUS service.
To enable or disable RADIUS service, issue the command:
aaaConfig ”--radius on | off“
Specifying
on
enables the service; specifying
off
disables it.
If no RADIUS configuration exists, turning it on triggers an error message. When the
command succeeds, an event is sent to the event log, indicating that the configuration is
enabled or disabled.
Position
The order in which servers are contacted to provide service
Server
The server names or IP addresses
Port
The server ports
Secret
The shared secrets
Timeouts
The length of time servers have to respond before the next server is
contacted
Authentication
The type of authentication being used on servers
where:
server
Is a server name or IP address. Avoid duplicating server listings
(that is, listing the same server once by name and again by IP
address). Up to five servers can be added to the configuration.
-p
port
Is an option; enter a server port. The default is port 1812.
-s
secret
Is an option; enter a shared secret. The default is
sharedsecret
.
Secrets can contain 8 to 40 alphanumeric characters.
-t
timeout
Is an option; enter the length of time (in seconds) the server has to
respond before the next server is contacted. The default is 3 seconds.
Timeout values can range from 1 to 30 seconds.
-a
Is an option; specify that the PAP protocol be used instead of the
CHAP protocol for packets traveling between the switch and the
server.