HP 10500 Series Configuration Manual page 33

Security configuration guide
Hide thumbs Also See for 10500 Series:
Table of Contents

Advertisement

Step
2.
Enter RADIUS scheme
view.
3.
Specify RADIUS
accounting servers.
4.
Set the maximum number
of real-time accounting
attempts.
5.
Enable buffering of
stop-accounting requests to
which no responses are
received.
6.
Set the maximum number
of stop-accounting
attempts.
Specifying the shared keys for secure RADIUS communication
The RADIUS client and RADIUS server use the MD5 algorithm to authenticate packets and use shared
keys for packet authentication and user password encryption. They must use the same key for the same
type of communication.
A shared key configured for a RADIUS scheme takes effect to all servers of the same type (accounting or
authentication) in the scheme, and has a lower priority than a key configured individually for a RADIUS
server.
A shared key configured on the device must be the same as that configured on the RADIUS server.
To specify a shared key for secure RADIUS communication:
Step
1.
Enter system view.
2.
Enter RADIUS scheme view.
3.
Specify a shared key for secure RADIUS
authentication/authorization or
accounting communication.
Specifying a VPN for the scheme
After you specify a VPN for a RADIUS scheme, all AAA servers specified for the scheme belong to the
VPN. However, if you also specify a VPN when specifying a server for the scheme, the server belongs to
the specific VPN.
Command
radius scheme radius-scheme-name
Specify the primary RADIUS accounting
server:
primary accounting { ip-address | ipv6
ipv6-address } [ port-number | key [ cipher |
simple ] key | vpn-instance
vpn-instance-name ] *
Specify a secondary RADIUS accounting
server:
secondary accounting { ip-address | ipv6
ipv6-address } [ port-number | key [ cipher |
simple ] key | vpn-instance
vpn-instance-name ] *
retry realtime-accounting retry-times
stop-accounting-buffer enable
retry stop-accounting retry-times
Command
system-view
radius scheme radius-scheme-name
key { accounting | authentication }
[ cipher | simple ] key
23
Remarks
N/A
Configure at least one
command.
No accounting server is
specified by default.
Optional.
The default setting is 5.
Optional.
Enabled by default.
Optional.
The default setting is
500.
Remarks
N/A
N/A
By default, no shared
key is specified.

Advertisement

Table of Contents
loading

Table of Contents