Operation Manual - Security
Quidway S3000 Series Ethernet Switches
Chapter 2 AAA and RADIUS Protocol Configuration
2-7
Table 2-6
Disconnect a user by force
Operation
Command
Disconnect a user
by force
cut connection
{
all
|
access-type
{
dot1x
|
gcm
} |
domain
domain-name
|
interface
interface-type interface-number
|
ip
ip-address
|
mac
mac-address
|
radius-scheme
radius-scheme-name
|
vlan
vlanid
|
ucibindex
ucib-index
|
user-name
user-name
}
By default, no online user will be disconnected by force.
2.3 Configure RADIUS Protocol
For the Quidway Series Ethernet Switches, the RADIUS protocol is configured on the
per RADIUS server group basis. In real networking environment, a RADIUS server
group can be an independent RADIUS server or a set of primary/second RADIUS
servers with the same configuration but two different IP addresses. Accordingly,
attributes of every RADIUS server group include IP addresses of primary and second
servers, shared key and RADIUS server type etc.
Actually, RADIUS protocol configuration only defines some necessary parameters
using for information interaction between NAS and RADIUS Server. To make these
parameters effective, it is necessary to configure, in the view, an ISP domain to use the
RADIUS server group and specify it to use RADIUS AAA schemes. For more about the
configuration commands, refer to the AAA Configuration section above.
RADIUS protocol configuration includes:
z
Create/Delete a RADIUS server group
z
Set IP Address and Port Number of RADIUS Server
z
Set RADIUS packet encryption key
z
Set response timeout timer of RADIUS server
z
Set retransmission times of RADIUS request packet
z
Set a real-time accounting interval
z
Set maximum times of real-time accounting request failing to be responded
z
Enable/Disable stopping accounting request buffer
z
Set the maximum retransmitting times of stopping accounting request
z
Set the Supported Type of RADIUS Server
z
Set RADIUS server state
z
Set username format transmitted to RADIUS server
z
Set the unit of data flow that transmitted to RADIUS server
z
Set local RADUIS server group
Among the above tasks, creating RADIUS server group and setting IP address of
RADIUS server are required, while other takes are optional and can be performed as
per your requirements.