HP 6125XLG R2306-HP 6125XLG Blade Switch Security Configuration Guide - Page 39

Configuring the IP addresses of the security policy servers, Displaying and maintaining RADIUS

Page 39 highlights

Step 3. Enable accounting-on. Command accounting-on enable [ interval seconds | send send-times ] * Remarks By default, the accounting-on feature is disabled. Configuring the IP addresses of the security policy servers The NAS verifies the validity of received control packets and accepts only control packets from known servers. To use a security policy server that is independent of the AAA servers, configure the IP address of the security policy server on the NAS. The security policy server is the management and control center of the HP EAD solution. To implement all EAD functions, configure both the IP address of the security policy server and that of the IMC Platform on the NAS. To configure the IP address of a security policy server for a scheme: Step 1. Enter system view. 2. Enter RADIUS scheme view. 3. Specify a security policy server. Command system-view Remarks N/A radius scheme radius-scheme-name N/A security-policy-server { ipv4-address | ipv6 ipv6-address } [ vpn-instance vpn-instance-name ] By default, no security policy server is specified for a scheme. You can specify up to eight security policy servers for a RADIUS scheme. Displaying and maintaining RADIUS Execute display commands in any view and reset commands in user view. Task Display the RADIUS scheme configuration. Display RADIUS packet statistics. Clear RADIUS statistics. Command display radius scheme [ radius-scheme-name ] display radius statistics reset radius statistics Configuring HWTACACS schemes Configuration task list Tasks at a glance (Required.) Creating an HWTACACS scheme (Required.) Specifying the HWTACACS authentication servers (Optional.) Specifying the HWTACACS authorization servers (Optional.) Specifying the HWTACACS accounting servers (Required.) Specifying the shared keys for secure HWTACACS communication 30

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276

30
Step
Command
Remarks
3.
Enable accounting-on.
accounting-on enable
[
interval
seconds
|
send
send-times
] *
By default, the accounting-on feature is
disabled.
Configuring the IP addresses of the security policy servers
The NAS verifies the validity of received control packets and accepts only control packets from known
servers. To use a security policy server that is independent of the AAA servers, configure the IP address
of the security policy server on the NAS.
The security policy server is the management and control center of the HP EAD solution. To implement all
EAD functions, configure both the IP address of the security policy server and that of the IMC Platform on
the NAS.
To configure the IP address of a security policy server for a scheme:
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter RADIUS scheme
view.
radius scheme
radius-scheme-name
N/A
3.
Specify a security policy
server.
security-policy-server
{
ipv4-address
|
ipv6
ipv6-address
} [
vpn-instance
vpn-instance-name
]
By default, no security policy server
is specified for a scheme.
You can specify up to eight security
policy servers for a RADIUS scheme.
Displaying and maintaining RADIUS
Execute
display
commands in any view and
reset
commands in user view.
Task
Command
Display the RADIUS scheme
configuration.
display radius scheme
[
radius-scheme-name
]
Display RADIUS packet statistics.
display radius statistics
Clear RADIUS statistics.
reset radius statistics
Configuring HWTACACS schemes
Configuration task list
Tasks at a glance
(Required.)
Creating an HWTACACS scheme
(Required.)
Specifying the HWTACACS authentication servers
(Optional.)
Specifying the HWTACACS authorization servers
(Optional.)
Specifying the HWTACACS accounting servers
(Required.)
Specifying the shared keys for secure HWTACACS communication