HP 10500 Series Configuration Manual page 39

Security configuration guide
Hide thumbs Also See for 10500 Series:
Table of Contents

Advertisement

To set RADIUS timers:
Step
1.
Enter system view.
2.
Enter RADIUS scheme view.
3.
Set the RADIUS server
response timeout timer.
4.
Set the quiet timer for the
servers.
5.
Set the real-time accounting
timer.
Configuring RADIUS accounting-on
The accounting-on feature enables a device to send an accounting-on packet to the RADIUS server after
it reboots so the server can log out users who logged in through the device before the reboot. Without this
feature, users who were online before the reboot could not re-log in after the reboot, because the RADIUS
server would consider them already online.
If a device sends an accounting-on packet to the RADIUS server but receives no response, it resends the
packet to the server at a particular interval for a specified number of times.
The accounting-on feature requires the cooperation of the HP IMC network management system.
To configure the accounting-on feature for a RADIUS scheme:
Step
1.
Enter system view.
2.
Enter RADIUS scheme
view.
3.
Enable accounting-on and
configure parameters.
Configuring the IP address of the security policy server
The core of the HP EAD solution is integration and cooperation. The security policy server is the
management and control center for EAD. Using a collection of software, the security policy server
provides functions such as user management, security policy management, security status assessment,
security cooperation control, and security event audit.
The NAS checks the validity of received control packets and accepts only control packets from known
servers. To use a security policy server that is independent of the AAA servers, you must configure the IP
address of the security policy server on the NAS. To implement all EAD functions, configure both the IP
address of the IMC security policy server and that of the IMC Platform on the NAS.
Command
system-view
radius scheme
radius-scheme-name
timer response-timeout seconds
timer quiet minutes
timer realtime-accounting minutes
Command
system-view
radius scheme
radius-scheme-name
accounting-on enable
[ interval seconds | send
send-times ] *
29
Remarks
N/A
N/A
Optional.
The default RADIUS server
response timeout timer is 3
seconds.
Optional.
The default quiet timer is 5 minutes.
Optional.
The default real-time accounting
timer is 12 minutes.
Remarks
N/A
N/A
Disabled by default.
The default interval is 3 seconds, and the
default number of send-times is 5.

Advertisement

Table of Contents
loading

Table of Contents