Operation Manual – AAA RADIUS HWTACACSH3C S9500 Series Routing SwitchesChapter 1 AAA, RADIUS and HWTACACSProtocol Configuration1-24To do... Use the command...Set the Supported Type of RADIUS Server server-type { extended | standard }Restore the Supported Type of RADIUSServer to the default setting undo server-typeBy default, the newly created RADIUS scheme supports the server of standard type,while the default RADIUS scheme system supports the server of extended type1.3.16 Setting RADIUS Server StateFor the primary and secondary servers (no matter it is an authentication/authorizationserver or accounting server), if the primary is disconnected to NAS for some fault, NASwill automatically turn to exchange packets with the secondary server. However, afterthe primary one recovers, NAS will not resume the communication with it at once,instead, it continues communicating with the secondary one. When the secondary onefails to communicate, NAS will turn to the primary one again. The following commandscan be used to set the primary server to be active manually, in order that NAS cancommunicate with it right after the troubleshooting.When both the primary and secondary servers are active or block, NAS will sendpackets to the primary server firstly. If NAS fails to connect the primary server, it willsend the packets to the secondary server.Perform the following operations in RADIUS scheme view to configure the state ofRADIUS server:To do... Use the command...Set the state of primary RADIUSauthentication/authorization serverstate primary authentication { block| active }Set the state of primary RADIUSaccounting serverstate primary accounting { block |active }Set the state of secondary RADIUSauthentication/authorization serverstate secondary authentication{ block | active }Set the state of secondary RADIUSaccounting serverstate secondary accounting { block| active }By default, the state of each server in RADIUS scheme server group is active.1.3.17 Setting the Username Format Transmitted to RADIUS ServerAs mentioned above, the supplicants are generally named in userid@isp-name format.The part following “@” is the ISP domain name. H3C Series Switches will put the usersinto different ISP domains according to the domain names. However, some earlierRADIUS servers reject the username including ISP domain name. In this case, you