beautypg.com

H3C Technologies H3C S5120 Series Switches User Manual

Page 426

background image

1-20

z

It is recommended to specify only the primary RADIUS authentication/authorization server if

backup is not required.

z

If both the primary and secondary authentication/authorization servers are specified, the

secondary one is used when the primary one is unreachable.

z

In practice, you may specify two RADIUS servers as the primary and secondary

authentication/authorization servers respectively. At one time, a server can be the primary

authentication/authorization server for a scheme and the secondary authentication/authorization

servers for another scheme.

z

The IP addresses of the primary and secondary authentication/authorization servers for a scheme

cannot be the same. Otherwise, the configuration fails.

Specifying the RADIUS Accounting Servers and Relevant Parameters

Follow these steps to specify the RADIUS accounting servers and perform related configurations:

To do…

Use the command…

Remarks

Enter system view

system-view

Enter RADIUS scheme view

radius scheme
radius-scheme-name

Specify the primary RADIUS
accounting server

primary accounting
ip-address [ port-number ]

Specify the secondary RADIUS
accounting server

secondary accounting
ip-address [ port-number ]

Required

Configure at least one of the
commands

No accounting server by default

Enable the device to buffer
stop-accounting requests
getting no responses

stop-accounting-buffer
enable

Optional

Enabled by default

Set the maximum number of
stop-accounting request
transmission attempts

retry stop-accounting
retry-times

Optional

500 by default

Set the maximum number of
accounting request
transmission attempts

retry realtime-accounting
retry-times

Optional

5 by default