beautypg.com

Creating a radius scheme, Specifying the radius authentication servers, Required.) – H3C Technologies H3C S6300 Series Switches User Manual

Page 38

background image

23

Tasks at a glance

(Optional.)

Setting the maximum number of RADIUS request transmission attempts

(Optional.)

Setting the status of RADIUS servers

(Optional.)

Specifying the source IP address for outgoing RADIUS packets

(Optional.)

Setting RADIUS timers

(Optional.)

Configuring the accounting-on feature

(Optional.)

Configuring the IP addresses of the security policy servers

(Optional.)

Configuring the Login-Service attribute check method for SSH, FTP, and terminal users

(Optional.)

Enabling SNMP notifications for RADIUS

(Optional.)

Displaying and maintaining RADIUS

Creating a RADIUS scheme

Create a RADIUS scheme before performing any other RADIUS configurations. You can configure a
maximum of 16 RADIUS schemes. A RADIUS scheme can be used by multiple ISP domains.
To create a RADIUS scheme:

Step Command

Remarks

1.

Enter system view.

system-view

N/A

2.

Create a RADIUS scheme and
enter RADIUS scheme view.

radius scheme
radius-scheme-name

The default setting depends on the
type of startup configuration used:

If the device starts up with initial

settings, no RADIUS scheme is

defined.

If the device starts up with the

factory defaults, a RADIUS

scheme named system is

defined.

For more information about the
startup configuration, see

Fundamentals Configuration

Guide.

Specifying the RADIUS authentication servers

A RADIUS authentication server completes authentication and authorization together, because
authorization information is piggybacked in authentication responses sent to RADIUS clients.
You can specify one primary authentication server and a maximum of 16 secondary authentication

servers for a RADIUS scheme. When the primary server is not available, the device searches for the

secondary servers in the order they are configured. The first secondary server in active state is used for
communication.
If redundancy is not required, specify only the primary server. A RADIUS authentication server can

function as the primary authentication server for one scheme and a secondary authentication server for

another scheme at the same time.
To specify RADIUS authentication servers for a RADIUS scheme: