Installation manual

Operation Manual - Security
Quidway S3000-EI Series Ethernet Switches
Chapter 2 AAA and RADIUS Protocol
Configuration
Huawei Technologies Proprietary
2-11
eme Table 2-11 Creating/Deleting a RADIUS sch
Operation Command
Create a RADIUS scheme and
enter its view
radius
scheme radius-scheme-name
Delete a RADIUS scheme
undo radius
scheme radius-scheme-name
Several ISP domains can use a RADIUS scheme at the same time. You can configure
up to 16 RADIUS schemes, includin
g the default scheme named as system.
med “system” whose attributes are all
default values. The default attribute values will be introduced in the following text.
2.3.2 Setting IP Address and Port Number of RADIUS Server
After creating a RADIUS e, you are supposed to set IP d UDP port
numbers for the RADIUS servers, includin /second
a ccounting servers. So you can configure up
to ort numbers. However, at least you have to set
ne group of IP address and UDP port number for each pair of primary/second servers
re the normal AAA operation.
figure the IP address and port number for
By default, the system has a RADIUS scheme na
schem addresses an
g primary
uthentication/authorization servers and a
4 groups of IP addresses and UDP p
o
to ensu
You can use the following commands to con
RADIUS servers.
Perform the following configurations in RADIUS scheme view.
Table 2-12 Setting IP Address and Port Number of RADIUS Server
Operation Command
Set IP address and port number of primary
RADIUS authen
primary authentication
tication/authorization server. ip-address [ port-number ]
Restore IP address and port number of
primary RADIUS authentication/authorization
or server to the default values.
undo primary authentication
Set IP address and port number of primary
RADIUS accounting server.
primary accounting ip-address
[ port-number ]
Restore IP address and port number of
primary RADIUS accounting server or server
undo primary accounting
to the default values.
Set IP address and port number of secondary
secondary authentication
port-number ]
RADIUS authentication/authorization server. ip-address [
R store IP address and port number e of
c
secondary authentication
se ond RADIUS authentication/authorization
undo
or server to the default values.