187| Authentication Servers DellPowerConnect W- Series ArubaOS 6.2 | User Guide
3. (Optio nal)In the Profile Detai lspane, select RAD IUS Interim Accounting to allow the controllerto s end
Interim-Update messageswi thc urrentuser statistics to t heserver at regular intervals.This opti oni s disabledby
default,allowing the controller to send only
start
and
stop
messages RADIUS accounting server.
4. I n the profilelist, scroll down and select the Radius Accounting Server Groupfor the AA A profile.Select the
servergroup from the drop-down menu.
You can add additional servers to the group or configure server rules.
5. Click A pply.
Using the CLI
(host)(config) #aaa profile <profile>
radius-accounting <group>
radius-interim-accounting

TACACS + Accounting

TACACS+ accounting allows commands issuedo nt heco ntrollerto be reported to TACACS+ servers. You can
specify the types of commands that are reported (action, configuration, or show co mmands)or have all commands
reported.
You can configureTA CACS+ accounting only with the CLI:
(host)(config) #aaa tacacs-accounting server-group <group> command
{action|all|configuration|show} mode {enable|disable}
Configuring Authent ication Timers
Table5 7 describes the timers you can configure that apply to all clients and servers. These timers can be left at their
defaultvalues for most i mplementations.

Timer Description

UserIdle Timeout Maximum period after which a client is considered idle if there is no wireless
trafficfrom the client.The timeout period i sreset if there is wireless traffic. If
thereis no wi relesstraffic in the timeout period, the cli enti saged out. Once the
timeoutperi od hasexpired, theuser is removed. If the keyword seconds is not
specified, thevalue defaults to minutes at the command line
Range: 1 to 255m inutes (30to 15300seconds)
Default:5 mi nutes(300 seconds)
AuthenticationServer Dead
Time
Maximum period, in minutes, that the controller considers an unresponsive
authenticationserver to be “out of service”.
Thistim er is only applicable if there are two or more authentication servers
configuredon the controller. Ifthere is only one authentication server configured,
theserver is never considered out of service and all requests are sentto the
server.
Ifone or more backup servers are configured and a server is unresponsive, it is
markedas out of service for the dead time; subsequent requestsare sent to the
nextserver on the priority list for the duration of thedead tim e. Ifthe server is
responsiveafter the dead time has elapsed, it can take over servicing requests
froma l ower-priority server; if theserver continues to be unresponsive, it is
markedas down for the dead time.
Range: 0–50m inutes
Default:10 minutes

Table57 :

AuthenticationTimers