151
To do… Use the command…
Remarks
Specify the portal group to which
the portal service backup interface
belongs
portal backup-group group-id
Required
By default, the portal service
backup interface does not belong
to any portal group.
The portal service backup
interfaces on the two devices for
stateful failover must belong to the
same portal group.
Return to system view quit —
Specify the device ID in stateful
failover mode
nas device-id device-id
Required
By default, the device works in
stand-alone mode, and thus has no
device ID configured.
For more information about the
command, see Security Command
Reference.
Specify the backup source IP
address for RADIUS packets to be
sent
radius nas-backup-ip ip-address Optional
Use either approach.
By default, no backup source IP
address is specified.
You do not need to specify the
backup source IP address if the
device uses the virtual IP address of
the VRRP group to which the uplink
belongs as the source IP address of
outgoing RADIUS packets.
For more information about the
command, see Security Command
Reference.
radius scheme
radius-scheme-name
nas-backup-ip ip-address
Note the following issues when configuring portal stateful failover:
• In stateful failover mode, the device does not support re-DHCP portal authentication on the portal
service backup interface.
• In stateful failover mode, if a user on either device is logged out, the information of the user on the
other device is deleted, too. You can log off a user on the device or on the portal server. For example,
you can use the cut connection and portal delete-user commands on the device to log off users.
• The AAA and portal configuration must be consistent on the two devices that back up each other.
For example, you must configure the same portal server on the two devices.
CAUTION:
• Specifying or changing the device ID of a device will log off all online users on the device. Therefore,
perform the confi
uration only when necessary and, after the confi
uration, save the confi
uration and
restart the device.
• When two devices are running in stateful failover mode (one active, the other standby), do not delete the
configured backup source IP addresses. Otherwise, online users on the backup may not be able to
receive packets from the server.