beautypg.com

H3C Technologies H3C WX3000E Series Wireless Switches User Manual

Page 38

background image

24

Step Command

Remarks

3.

Specify RADIUS

authentication/authorization

servers.

Specify the primary RADIUS
authentication/authorization

server:

primary authentication
{ ip-address | ipv6

ipv6-address } [ port-number |

key [ cipher | simple ] key |
probe username name [ interval

interval ] ] *

Specify a secondary RADIUS

authentication/authorization

server:

secondary authentication

{ ip-address | ipv6
ipv6-address } [ port-number |

key [ cipher | simple ] key |

probe username name [ interval
interval ] ] *

Configure at least one command.
No authentication/authorization

server is specified by default.

NOTE:

The IP addresses of the primary and secondary authentication/authorization servers for a scheme must
be different from each other. Otherwise, the configuration will fail.

All servers for authentication/authorization and accountings, primary or secondary, must use IP
addresses of the same IP version.

You can specify a RADIUS authentication/authorization server as the primary
authentication/authorization server for one scheme and as the secondary authentication/authorization

server for another scheme at the same time.

Specifying the RADIUS accounting servers and the relevant parameters

You can specify one primary accounting server and up to 16 secondary accounting servers for a RADIUS

scheme. When the primary server is not available, a secondary server is used, if any. When redundancy

is not required, specify only the primary server.
By setting the maximum number of real-time accounting attempts for a scheme, you make the device

disconnect users for whom no accounting response is received before the number of accounting attempts

reaches the limit.
When the device receives a connection teardown request from a host or a connection teardown

notification from an administrator, it sends a stop-accounting request to the accounting server. You can
enable buffering of non-responded stop-accounting requests to allow the device to buffer and resend a

stop-accounting request until it receives a response or the number of stop-accounting attempts reaches

the configured limit. In the latter case, the device discards the packet.
To specify RADIUS accounting servers and set relevant parameters for a scheme:

Step Command

Remarks

1.

Enter system view.

system-view

N/A

2.

Enter RADIUS scheme view.

radius scheme radius-scheme-name N/A