Got it

Notice to Be Taken AR Connects to H3C RADIUS Servers

Latest reply: Jun 21, 2017 02:57:10 1382 1 0 0 0

When the device connects to an H3C iMC RADIUS server to perform authentication, authorization, or accounting for 802.1x users, configure security check policies (for example, check whether the 802.1x client has two network cards and whether the 802.1x client version is correct) on the RADIUS server to improve security. In addition, perform the following operations on the device:

1.      Configure RADIUS accounting.

2.      Run the dot1x authentication-method eap command to configure EAP relay authentication for 802.1x users.

3.      Run the dot1x eap-notify-packet eap-code 10 data-type 25 command to configure the device to return the EAP packets with type value of 10 and data type of 25 to the RADIUS server.

4.      Run the radius-attribute translate HW-Up-Priority HW-User-Information receive command to convert the HW-Up-Priority attribute in the received RADIUS packets into HW-User-Information.

5.      If the RADIUS server needs to dynamically authorize AAA users, the attributes delivered by security check policy may be different from the attributes delivered by dynamic authorization. Therefore, run the authorization-modify mode modify command to set the update mode for user authorization information delivered by the RADIUS server to Modify. After the command is executed, the attributes delivered by dynamic authorization will not overwrite the attributes delivered by security check policy.

6.      To use the session management function, run the radius-server session-manage ip-address shared-key cipher share-key command to enable session management on the RADIUS server and set the IP address and shared key of the RADIUS session management server.



  • x
  • convention:

Created Jun 21, 2017 02:57:10

View more
  • x
  • convention:


You need to log in to comment to the post Login | Register

Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " User Agreement."

My Followers

Login and enjoy all the member benefits


Are you sure to block this user?
Users on your blacklist cannot comment on your post,cannot mention you, cannot send you private messages.
Please bind your phone number to obtain invitation bonus.
Information Protection Guide
Thanks for using Huawei Enterprise Support Community! We will help you learn how we collect, use, store and share your personal information and the rights you have in accordance with Privacy Policy and User Agreement.