Configuration Guide Configuring RADIUS
Configuring the Remote RADIUS Security Server
Mandatory.
Configure the IP address, authentication port, accounting port, and shard key of the RADIUS security server.
Configuring the Shared Key for Communication Between the Device and the RADIUS Server
Optional.
Configure a shared key in global configuration mode for servers without a shared key.
The shared key on the device must be consistent with that on the RADIUS server.
Configuring the Request Transmission Count, After Which the Device Confirms That a RADIUS Server Is
Unreachable
Optional.
Configure the request transmission count, after which the device confirms that a RADIUS server is unreachable,
according to the actual network environment.
Configuring the Waiting Time, After which the Device Retransmits a Request
Optional.
Configure the waiting time, after which the device retransmits a request, according to the actual network environment.
In an 802.1X authentication environment that uses the RADIUS security protocol, if a network device serves as the
802.1X authenticator and Ruijie SU is used as the 802.1X client software, it is recommended that radius-server
timeout be set to 3 seconds (the default value is 5 seconds) and radius-server retransmit be set to 2 (the default
value is 3) on the network device.
Configuring Retransmission of Accounting Update Packets for Authenticated Users
Optional.
Determine whether to enable the function of retransmitting accounting update packets of authenticated users according
to actual requirements.
Configuring the Source Address of RADIUS Packets
Optional.
Configure the source address of RADIUS packets according to the actual network environment.
Verification
Configure the AAA method list that specifies to conduct authentication, authorization, and accounting on users by using
RADIUS.
Enable the device to interact with the RADIUS server. Conduct packet capture to confirm that the device communicates
with the RADIUS server over the RADIUS protocol.