R211x-HP Flexfabric 11900 Security Command Reference

Table Of Contents
44
The shared key configured by using this command takes precedence over the shared key configured with
the key accounting command.
If the specified server resides on an MPLS L3VPN, specify the VPN by using the vpn-instance
vpn-instance-name option. The VPN specified by this command takes precedence over the VPN
specified for the RADIUS scheme.
If you use the primary accounting command to modify or delete the primary accounting server to which
the device is sending a start-accounting request, communication with the primary server times out. The
device tries to communicate with an active server that has the highest priority for accounting.
If you remove an actively used accounting server, the device no longer sends users' real-time accounting
requests and stop-accounting requests. It does not buffer the stop-accounting requests. The device can
generate incorrect accounting results.
For security purposes, all shared keys, including shared keys configured in plain text, are saved in
ciphertext.
Examples
# Specify the primary accounting server with IP address 10.110.1.2, UDP port number 1813, and plaintext
shared key 123456TESTacct&! for RADIUS scheme radius1.
<Sysname> system-view
[Sysname] radius scheme radius1
[Sysname-radius-radius1] primary accounting 10.110.1.2 1813 key simple 123456TESTacct&!
Related commands
display radius scheme
key (RADIUS scheme view)
secondary accounting (RADIUS scheme view)
vpn-instance (RADIUS scheme view)
primary authentication (RADIUS scheme view)
Use primary authentication to specify the primary RADIUS authentication server.
Use undo primary authentication to remove the configuration.
Syntax
primary authentication { ipv4-address | ipv6 ipv6-address } [ port-number | key { cipher | simple }
string | vpn-instance vpn-instance-name ] *
undo primary authentication
Default
No primary RADIUS authentication server is specified.
Views
RADIUS scheme view
Predefined user roles
network-admin
mdc-admin