secondary servers with the same configuration but different IP addresses) in a RADIUS scheme. After creating a new RADIUS scheme, you should configure the IP address and UDP port number of each RADIUS server you want to use in this scheme. These RADIUS servers fall into two types: authentication/authorization, and accounting. And for each type of server, you can configure two servers in a RADIUS scheme: primary server and secondary server. A RADIUS scheme has some parameters such as IP addresses of the primary and secondary servers, shared keys, and types of the RADIUS servers.

In an actual network environment, you can configure the above parameters as required. But you should configure at least one authentication/authorization server and one accounting server, and you should keep the RADIUS server port settings on the device consistent with those on the RADIUS servers.

Actually, the RADIUS service configuration only defines the parameters for information exchange between device and RADIUS server. To make these parameters take effect, you must reference the RADIUS scheme configured with these parameters in an ISP domain view (refer to AAA Configuration).

Creating a RADIUS Scheme

The RADIUS protocol configuration is performed on a RADIUS scheme basis. You should first create a RADIUS scheme and enter its view before performing other RADIUS protocol configurations.

Follow these steps to create a RADIUS scheme:

 

 

To do…

 

Use the command…

 

Remarks

 

 

 

Enter system view

 

system-view

 

 

 

 

 

 

 

 

 

 

 

 

Enable RADIUS authentication

 

 

 

Optional

 

 

 

 

radius client enable

 

By default, RADIUS

 

 

 

port

 

 

 

 

 

 

 

 

authentication port is enabled.

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Required

 

 

 

Create a RADIUS scheme and

 

radius scheme

 

By default, a RADIUS scheme

 

 

 

enter its view

 

radius-scheme-name

 

named "system" has already

 

 

 

 

 

 

 

been created in the system.

 

 

 

 

 

 

 

 

 

A RADIUS scheme can be referenced by multiple ISP domains simultaneously.

Configuring RADIUS Authentication/Authorization Servers

Follow these steps to configure RADIUS authentication/authorization servers:

2-10

Page 269
Image 269
3Com WX3000 Creating a Radius Scheme, Configuring Radius Authentication/Authorization Servers, Radius client enable