HP 12500 Series Configuration Manual page 43

Routing
Table of Contents

Advertisement

succeed because the switch has set the state of the unreachable servers to blocked and the time for
finding a reachable server is shortened.
For more information about the maximum number of RADIUS packet transmission attempts, see
"Setting the maximum number of RADIUS request transmission
Set the server quiet timer properly. Too short a quiet timer may result in frequent authentication or
accounting failures because the switch has to repeatedly attempt to communicate with an
unreachable server that is in active state.
To set timers for controlling communication with RADIUS servers:
Step
1.
Enter system view.
2.
Enter RADIUS scheme view.
3.
Set the RADIUS server
response timeout timer.
4.
Set the quiet timer for the
servers.
5.
Set the real-time accounting
timer.
Configuring RADIUS accounting-on
The accounting-on feature enables a switch to send accounting-on packets to the RADIUS server after it
reboots, making the server log out users who logged in through the switch before the reboot. Without this
feature, users who were online before the reboot cannot re-log in after the reboot, because the RADIUS
server considers they are already online.
If a switch sends an accounting-on packet to the RADIUS server but receives no response, it resends the
packet to the server at a particular interval for a specified number of times.
The accounting-on feature requires the cooperation of the HP IMC network management system.
To configure the accounting-on feature for a RADIUS scheme:
Step
1.
Enter system view.
2.
Enter RADIUS scheme
view.
3.
Enable accounting-on and
configure parameters.
Configuring the IP address of the security policy server
The core of the HP EAD solution is integration and cooperation, and the security policy server is the
management and control center. Using a collection of software, the security policy server provides
functions such as user management, security policy management, security status assessment, security
cooperation control, and security event audit.
Command
system-view
radius scheme
radius-scheme-name
timer response-timeout seconds
timer quiet minutes
timer realtime-accounting minutes
Command
system-view
radius scheme
radius-scheme-name
accounting-on enable
[ interval seconds | send
send-times ] *
33
attempts."
Remarks
N/A
N/A
Optional.
3 seconds by default.
Optional.
5 minutes by default.
Optional.
12 minutes by default.
Remarks
N/A
N/A
Disabled by default.
The default interval is 3 seconds and the
default number of send-times is 5.

Advertisement

Table of Contents
loading

Table of Contents