received from each other by using the shared keys that have been set on them, and can accept and respond to the messages only when both parties have the same shared key.

Follow these steps to configure shared keys for RADIUS messages:

 

To do…

Use the command…

Remarks

 

 

Enter system view

system-view

 

 

 

 

 

 

 

 

 

Required

 

 

Create a RADIUS scheme and

radius scheme

By default, a RADIUS scheme

 

 

enter its view

radius-scheme-name

named "system" has already

 

 

 

 

been created in the system.

 

 

 

 

 

 

 

Set a shared key for RADIUS

 

Required

 

 

authentication/authorization

key authentication string

By default, no shared key is

 

 

messages

 

created.

 

 

 

 

 

 

 

Set a shared key for RADIUS

 

Required

 

 

key accounting string

By default, no shared key is

 

 

accounting messages

 

 

 

created.

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

The authentication/authorization shared key and the accounting shared key you set on the device must be respectively consistent with the shared key on the authentication/authorization server and the shared key on the accounting server.

Configuring the Maximum Number of RADIUS Request Transmission Attempts

The communication in RADIUS is unreliable because this protocol uses UDP packets to carry its data. Therefore, it is necessary for the device to retransmit a RADIUS request if it gets no response from the RADIUS server after the response timeout timer expires. If the device gets no answer after it has tried the maximum number of times to transmit the request, the device considers that the request fails.

Follow these steps to configure the maximum transmission attempts of a RADIUS request:

To do…

Use the command…

Remarks

Enter system view

system-view

 

 

 

 

 

Required

Create a RADIUS scheme and

radius scheme

By default, a RADIUS scheme

enter its view

radius-scheme-name

named "system" has already been

 

 

created in the system.

 

 

 

Set the maximum number of

 

Optional

RADIUS request transmission

retry retry-times

By default, the system can try three

attempts

 

times to transmit a RADIUS request.

 

 

 

Configuring the Type of RADIUS Servers to be Supported

Follow these steps to configure the type of RADIUS servers to be supported:

2-13

Page 272
Image 272
3Com WX3000 Configuring the Type of Radius Servers to be Supported, Key authentication string, Key accounting string