To do…

 

Use the command…

 

Remarks

 

 

 

 

 

 

Optional

 

 

 

Set the IP address and port

 

 

By default, the IP address and

 

 

 

 

secondary accounting

UDP port number of the

 

 

 

number of the secondary

 

secondary accounting server

 

 

 

ip-address [ port-number ]

 

 

 

RADIUS accounting server

are 0.0.0.0 and 1813 for a

 

 

 

 

 

 

 

 

 

 

 

newly created RADIUS

 

 

 

 

 

 

scheme.

 

 

 

 

 

 

 

 

 

 

 

Enable stop-accounting

 

stop-accounting-buffer

 

Optional

 

 

 

 

 

By default, stop-accounting

 

 

 

request buffering

 

enable

 

 

 

 

 

 

request buffering is enabled.

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Set the maximum number of

 

 

 

Optional

 

 

 

 

 

 

By default, the system tries at

 

 

 

transmission attempts of a

 

retry stop-accounting

 

 

 

 

 

 

most 500 times to transmit a

 

 

 

buffered stop-accounting

 

retry-times

 

 

 

 

 

 

buffered stop-accounting

 

 

 

request.

 

 

 

 

 

 

 

 

 

request.

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Optional

 

 

 

Set the maximum allowed

 

 

 

By default, the maximum

 

 

 

 

retry realtime-accounting

 

allowed number of continuous

 

 

 

number of continuous real-time

 

 

real-time accounting failures is

 

 

 

accounting failures

 

retry-times

 

five. If five continuous failures

 

 

 

 

 

 

 

 

 

 

 

 

 

occur, the device cuts down the

 

 

 

 

 

 

 

user connection.

 

 

 

 

 

 

 

 

 

zIn an actual network environment, you can specify one server as both the primary and secondary accounting servers, as well as specifying two RADIUS servers as the primary and secondary accounting servers respectively. In addition, because RADIUS adopts different UDP ports to exchange authentication/authorization messages and accounting messages, you must set a port number for accounting different from that set for authentication/authorization.

zWith stop-accounting request buffering enabled, the device first buffers the stop-accounting request that gets no response from the RADIUS accounting server, and then retransmits the request to the RADIUS accounting server until it gets a response, or the maximum number of transmission attempts is reached (in this case, it discards the request).

zYou can set the maximum allowed number of continuous real-time accounting failures. If the number of continuously failed real-time accounting requests to the RADIUS server reaches the set maximum number, the device cuts down the user connection.

zThe IP address and port number of the primary accounting server of the default RADIUS scheme "system" are 127.0.0.1 and 1646 respectively.

zCurrently, RADIUS does not support the accounting of FTP users.

Configuring Shared Keys for RADIUS Messages

Both RADIUS client and server adopt MD5 algorithm to encrypt RADIUS messages before they are exchanged between the two parties. The two parties verify the validity of the RADIUS messages

2-12

Page 271
Image 271
3Com WX3000 operation manual Configuring Shared Keys for Radius Messages, Secondary accounting, Stop-accounting-buffer