1-23To do… Use the command… RemarksEnter system view system-view —Enter RADIUS scheme view radius schemeradius-scheme-name —Specify the primary RADIUSaccounting serverprimary accountingip-address [ port-number ]Specify the secondary RADIUSaccounting serversecondary accountingip-address [ port-number ]RequiredConfigure at least one of thecommandsNo accounting server by defaultEnable the device to bufferstop-accounting requestsgetting no responsesstop-accounting-bufferenableOptionalEnabled by defaultSet the maximum number ofstop-accounting requesttransmission attemptsretry stop-accountingretry-timesOptional500 by defaultSet the maximum number ofaccounting requesttransmission attemptsretry realtime-accountingretry-timesOptional5 by defaultz It is recommended to specify only the primary RADIUS accounting server if backup is not required.z If both the primary and secondary accounting servers are specified, the secondary one is usedwhen the primary one is not reachable.z In practice, you can specify two RADIUS servers as the primary and secondary accounting serversrespectively, or specify one server to function as the primary accounting server in a scheme andthe secondary accounting server in another scheme. Besides, because RADIUS uses differentUDP ports to receive authentication/authorization and accounting packets, the port forauthentication/authorization must be different from that for accounting.z You can set the maximum number of stop-accounting request transmission buffer, allowing thedevice to buffer and resend a stop-accounting request until it receives a response or the number oftransmission retries reaches the configured limit. In the latter case, the device discards the packet.z You can set the maximum number of accounting request transmission attempts on the device,allowing the device to disconnect a user when the number of accounting request transmissionattempts for the user reaches the limit but it still receives no response to the accounting request.z The IP addresses of the primary and secondary accounting servers cannot be the same. Otherwise,the configuration fails.z Currently, RADIUS does not support keeping accounts on FTP users.Setting the Shared Key for RADIUS PacketsThe RADIUS client and RADIUS server use the MD5 algorithm to encrypt packets exchanged betweenthem and a shared key to verify the packets. Only when the same key is used can they properly receivethe packets and make responses.Follow these steps to set the shared key for RADIUS packets: