R3204P16-HP Load Balancing Module Security Configuration Guide-6PW101

152
To do… Use the command…
Remarks
Set the quiet timer for the primary
server
timer quiet minutes
Optional
5 minutes by default
Set the real-time accounting
interval
timer realtime-accounting minutes
Optional
12 minutes by default
NOTE:
The maximum number of retransmission attempts of RADIUS packets multiplied by the RADIUS server
response timeout period must be less than 75 and the upper limit of this product is determined by the
upper limit of the timeout time of different access modules.
For an access module, the maximum number of retransmission attempts multiplied by the RADIUS
server response timeout period must be smaller than the timeout time. Otherwise, stop-accounting
messages cannot be buffered, and the primary/secondary server switchover cannot take place. For
example, as the timeout time of voice access is 10 seconds, the product of the two parameters cannot
exceed 10 seconds; as the timeout time of Telnet access is 30 seconds, the product of the two parameters
cannot exceed 30 seconds.
To configure the maximum number of retransmission attempts of RADIUS packets, use the retry
command.
Configuring RADIUS accounting-on
The accounting-on feature enables the LB module to send accounting-on packets to the RADIUS server
after it reboots, making the server log out users who logged in through the LB module before the reboot.
Without this feature, users who were online before the reboot cannot re-log in after the reboot, because
the RADIUS server considers they are already online.
If a LB module sends an accounting-on packet to the RADIUS server but receives no response, it resends
the packet to the server at a particular interval for a specified number of times.
Follow these steps to configure the accounting-on feature for a RADIUS scheme:
To do… Use the command…
Remarks
Enter system view system-view
Enter RADIUS scheme view
radius scheme
radius-scheme-name
Enable accounting-on accounting-on enable
Required
Disabled by default
Set the number of accounting-on
packet retransmission attempts
accounting-on enable send
send-times
Optional
5 times by default
Set the retransmission interval of
accounting-on packets
accounting-on enable interval
seconds
Optional
3 seconds by default
NOTE:
The accounting-on feature requires the cooperation of the HP IMC network management system.