HP 6125XLG R2306-HP 6125XLG Blade Switch Security Configuration Guide - Page 33

Specifying the RADIUS accounting servers and the relevant parameters, Command, Remarks, active

Page 33 highlights

Step 2. Enter RADIUS scheme view. 3. Specify RADIUS authentication servers. Command Remarks radius scheme radius-scheme-name N/A • Specify the primary RADIUS authentication server: primary authentication { ipv4-address | ipv6 ipv6-address } Configure at least one command. [ port-number | key { cipher | By default, no authentication server simple } string | vpn-instance is specified. vpn-instance-name ] * Two authentication servers in a • Specify a secondary RADIUS scheme, primary or secondary, authentication server: cannot have the same combination secondary authentication of IP address, port number, and { ipv4-address | ipv6 ipv6-address } VPN. [ port-number | key { cipher | simple } string | vpn-instance vpn-instance-name ] * Specifying the RADIUS accounting servers and the relevant parameters You can specify one primary accounting server and up to 16 secondary accounting servers for a RADIUS scheme. When the primary server is not available, the device tries to communicate with the secondary servers in the order they are configured, and communicates with the first secondary server in active state. When redundancy is not required, specify only the primary server. A RADIUS accounting server can function as the primary accounting server for one scheme and a secondary accounting server for another scheme at the same time. When the device receives a connection teardown request from a host or a connection teardown command from an administrator, it sends a stop-accounting request to the accounting server. When the maximum number of real-time accounting attempts is reached, the device disconnects users who have no accounting responses. RADIUS does not support accounting for FTP users. To specify RADIUS accounting servers and the relevant parameters for a RADIUS scheme: Step 1. Enter system view. 2. Enter RADIUS scheme view. 3. Specify RADIUS accounting servers. Command Remarks system-view N/A radius scheme radius-scheme-name • Specify the primary RADIUS accounting server: primary accounting { ipv4-address | ipv6 ipv6-address } [ port-number | key { cipher | simple } string | vpn-instance vpn-instance-name ] * • Specify a secondary RADIUS accounting server: secondary accounting { ipv4-address | ipv6 ipv6-address } [ port-number | key { cipher | simple } string | vpn-instance vpn-instance-name ] * N/A Configure at least one command. By default, no accounting server is specified. Two accounting servers in a scheme, primary or secondary, cannot have the same combination of IP address, port number, and VPN. 24

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276

24
Step
Command
Remarks
2.
Enter RADIUS scheme
view.
radius scheme
radius-scheme-name
N/A
3.
Specify RADIUS
authentication servers.
Specify the primary RADIUS
authentication server:
primary authentication
{
ipv4-address
|
ipv6
ipv6-address
}
[
port-number
|
key
{
cipher
|
simple
}
string
|
vpn-instance
vpn-instance-name
] *
Specify a secondary RADIUS
authentication server:
secondary
authentication
{
ipv4-address
|
ipv6
ipv6-address
}
[
port-number
|
key
{
cipher
|
simple
}
string
|
vpn-instance
vpn-instance-name
] *
Configure at least one command.
By default, no authentication server
is specified.
Two authentication servers in a
scheme, primary or secondary,
cannot have the same combination
of IP address, port number, and
VPN.
Specifying the RADIUS accounting servers and the relevant parameters
You can specify one primary accounting server and up to 16 secondary accounting servers for a RADIUS
scheme. When the primary server is not available, the device tries to communicate with the secondary
servers in the order they are configured, and communicates with the first secondary server in
active
state.
When redundancy is not required, specify only the primary server. A RADIUS accounting server can
function as the primary accounting server for one scheme and a secondary accounting server for
another scheme at the same time.
When the device receives a connection teardown request from a host or a connection teardown
command from an administrator, it sends a stop-accounting request to the accounting server. When the
maximum number of real-time accounting attempts is reached, the device disconnects users who have no
accounting responses.
RADIUS does not support accounting for FTP users.
To specify RADIUS accounting servers and the relevant parameters for a RADIUS scheme:
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter RADIUS scheme view.
radius scheme
radius-scheme-name
N/A
3.
Specify RADIUS accounting
servers.
Specify the primary RADIUS
accounting server:
primary accounting
{
ipv4-address
|
ipv6
ipv6-address
} [
port-number
|
key
{
cipher
|
simple
}
string
|
vpn-instance
vpn-instance-name
] *
Specify a secondary RADIUS
accounting server:
secondary accounting
{
ipv4-address
|
ipv6
ipv6-address
}
[
port-number
|
key
{
cipher
|
simple
}
string
|
vpn-instance
vpn-instance-name
] *
Configure at least one
command.
By default, no accounting
server is specified.
Two accounting servers in a
scheme, primary or
secondary, cannot have the
same combination of IP
address, port number, and
VPN.