3Com Switch 8800 Configuration Guide Chapter 40 AAA and RADIUS/TACACS+ Protocol Con
figuration
40-13
Among the above tasks, creating RADIUS scheme and setting IP address of RADIUS
server are required, while other takes are optional and can be performed as your
requirements.
40.3.1 Creating/Deleting a RADIUS scheme
As mentioned above, RADIUS protocol configurations are performed on the per
RADIUS scheme basis. Therefore, before performing other RADIUS protocol
configurations, it is compulsory to create the RADIUS scheme and enter its view.
You can use the following commands to create/delete a RADIUS scheme.
Perform the following configuration in system view.
Table 40-10 Create/Delete a RADIUS server group
Operation Command
Create a RADIUS server group and
enter its view radius scheme radius-server-name
Delete a RADIUS server group undo radius scheme radius-server-name
Several ISP domains can use a RADIUS server group at the same time. You can
configure up to 16 RADIUS schemes, including the default server group named as
System.
By default, the system has a RADIUS scheme named “system” whose attributes are all
default values.
40.3.2 Setting IP Address and Port Number of a RADIUS Server
After creating a RADIUS scheme, you are supposed to set IP addresses and UDP port
numbers for the RADIUS servers, including primary/secondary
authentication/authorization servers and accounting servers. So you can configure up
to 4 groups of IP addresses and UDP port numbers. However, at least you have to set
one group of IP address and UDP port number for each pair of primary/secondary
servers to ensure the normal AAA operation.
You can use the following commands to configure the IP address and port number for
RADIUS schemes.
Perform the following configuration in RADIUS scheme view.