Creating a radius scheme, Specifying the radius authentication servers, Required.) – H3C Technologies H3C S6300 Series Switches User Manual
Page 38
23
Tasks at a glance
(Optional.)
Setting the maximum number of RADIUS request transmission attempts
(Optional.)
Setting the status of RADIUS servers
(Optional.)
Specifying the source IP address for outgoing RADIUS packets
(Optional.)
(Optional.)
Configuring the accounting-on feature
(Optional.)
Configuring the IP addresses of the security policy servers
(Optional.)
Configuring the Login-Service attribute check method for SSH, FTP, and terminal users
(Optional.)
Enabling SNMP notifications for RADIUS
(Optional.)
Displaying and maintaining RADIUS
Creating a RADIUS scheme
Create a RADIUS scheme before performing any other RADIUS configurations. You can configure a
maximum of 16 RADIUS schemes. A RADIUS scheme can be used by multiple ISP domains.
To create a RADIUS scheme:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Create a RADIUS scheme and
enter RADIUS scheme view.
radius scheme
radius-scheme-name
The default setting depends on the
type of startup configuration used:
•
If the device starts up with initial
settings, no RADIUS scheme is
defined.
•
If the device starts up with the
factory defaults, a RADIUS
scheme named system is
defined.
For more information about the
startup configuration, see
Fundamentals Configuration
Guide.
Specifying the RADIUS authentication servers
A RADIUS authentication server completes authentication and authorization together, because
authorization information is piggybacked in authentication responses sent to RADIUS clients.
You can specify one primary authentication server and a maximum of 16 secondary authentication
servers for a RADIUS scheme. When the primary server is not available, the device searches for the
secondary servers in the order they are configured. The first secondary server in active state is used for
communication.
If redundancy is not required, specify only the primary server. A RADIUS authentication server can
function as the primary authentication server for one scheme and a secondary authentication server for
another scheme at the same time.
To specify RADIUS authentication servers for a RADIUS scheme: