3Com 7750 Series Switch User Manual


  Open as PDF
of 1177
 
3Com Switch 7750 Series
Command Reference Guide – AAA, RADIUS, HWTACACS, EAD
Chapter 1 AAA & RADIUS & HWTACACS
Configuration Commands
1-47
View
RADIUS scheme view
Parameter
primary: Specifies the server to be set is a primary RADIUS server.
secondary: Specifies the server to be set is a secondary RADIUS server.
accounting: Specifies the server to be set is a RADIUS accounting server.
authentication: Specifies the server to be set is a RADIUS
authentication/authorization server.
block: Sets the status of the specified RADIUS server to block (that is, the down state).
active: Sets the status of the specified RADIUS server to active (that is, the normal
working state).
Description
Use the state command to set the status of a RADIUS server.
By default, all the RADIUS servers in a user-defined RADIUS scheme are in the block
state.
For the primary and secondary servers (authentication/authorization servers, or
accounting servers) in a RADIUS scheme, note that:
z When the NAS fails to communicate with the primary server due to some server
trouble, the NAS will actively exchange packets with the secondary server.
z After the primary server recovers, the NAS does not immediately restore the
communication with the primary server, but keeps communicating with the
secondary server unit the secondary server also fails. In order for the NAS to
quickly restore the communication with the recovered primary server, you need to
manually set the state of the primary server to active by using the state command.
z When both the primary and secondary servers are in the active state, the NAS
sends packets to the primary server only.
Related command: radius scheme, primary authentication, secondary
authentication, primary accounting, and secondary accounting.
Example
# Set the status of the secondary authentication server in RADIUS scheme radius1 to
active.
<3Com>system-view
System View: return to User View with Ctrl+Z.
[3Com] radius scheme radius1
[3Com-radius-radius1] state secondary authentication active