HP 6120XG HP ProCurve Series 6120 Blade Switches Access Security Guide - Page 206
Operating Rules for RADIUS Accounting, Steps for Configuring RADIUS Accounting, show radius
View all HP 6120XG manuals
Add to My Manuals
Save this manual to your list of manuals |
Page 206 highlights
RADIUS Authentication, Authorization, and Accounting Configuring RADIUS Accounting Operating Rules for RADIUS Accounting ■ You can configure up to four types of accounting to run simultaneously: exec, system, network, and commands. ■ RADIUS servers used for accounting are also used for authentication. ■ The switch must be configured to access at least one RADIUS server. ■ RADIUS servers are accessed in the order in which their IP addresses were configured in the switch. Use show radius to view the order. As long as the first server is accessible and responding to authentication requests from the switch, a second or third server will not be accessed. (For more on this topic, refer to "Changing RADIUS-Server Access Order" on page 5-50.) ■ If access to a RADIUS server fails during a session, but after the client has been authenticated, the switch continues to assume the server is available to receive accounting data. Thus, if server access fails during a session, it will not receive accounting data transmitted from the switch. Steps for Configuring RADIUS Accounting 1. Configure the switch for accessing a RADIUS server. You can configure a list of up to three RADIUS servers (one primary, two backup). The switch operates on the assumption that a server can operate in both accounting and authentication mode. (Refer to the documentation for your RADIUS server application.) • Use the same radius-server host command that you would use to configure RADIUS authentication. Refer to "3. Configure the Switch To Access a RADIUS Server" on page 5-14. • Provide the following: - A RADIUS server IP address. - Optional-a UDP destination port for authentication requests. Otherwise the switch assigns the default UDP port (1812; recommended). - Optional-if you are also configuring the switch for RADIUS authentication, and need a unique encryption key for use during authentication sessions with the RADIUS server you are designating, configure a server-specific key. This key overrides the global encryption key you can also configure on the switch, and 5-39