HP procurve 2500 Manuale Utente

Pagina di 270
105    
Enhancements in Release F.04.08
Configuring RADIUS Authentication and Accounting
Configuring the Switch for RADIUS Authentication
• If you need to replace the default UDP destination port  (1812) the switch uses for authentication requests to a specific 
RADIUS server, select it before beginning the configuration process.
• If you need to replace the default UDP destination port  (1813) the switch uses for accounting requests to a specific 
Radius server, select it before beginning the configuration process.
• Determine whether you can use one, global encryption key for all RADIUS servers or if  unique keys will be required 
for specific servers. With multiple RADIUS servers, if one key applies to two or more of these servers, then you can  
configure this key as the global encryption key. For any server whose key differs from the global key you are using,  
you must configure that key in the same command that you use to designate that server’s IP address to the switch. 
• Determine an acceptable timeout period for the switch to wait for a server to respond to a request. HP recommends 
that you begin with the default (five seconds).
• Determine how many times you want the switch to try contacting a RADIUS server before trying another RADIUS 
server or quitting. (This depends on how many RADIUS servers you have configured the switch to access.)
• Determine whether you want  to bypass a RADIUS server that fails to respond to requests for service. To shorten 
authentication  time, you can set a bypass period in the range of 1 to 1440 minutes for non-responsive servers. This 
requires that you have multiple RADIUS servers accessible for service requests.
RADIUS Authentication Commands
aaa authentication
       < console | telnet | ssh >  < enable | login > radius 
             < local | none >
[no] radius-server host < IP-address >
      [auth-port < port-number >]
      [acct-port < port-number >]
      [key < server-specific key-string >]
[no] radius-server key < global key-string >
page 111
radius-server timeout < 1 .. 15>
page 111
radius-server retransmit < 1 .. 5 >
page 111
[no] radius-server dead-time < 1 .. 1440 >
page 112
show radius 
      [< host < ip-address>]
page 122
show authentication
page 124
show radius authentication
page 124