Bind-Attribute - HP FlexNetwork 7500 Series Command Reference Manual

Hide thumbs Also See for FlexNetwork 7500 Series:
Table of Contents

Advertisement

[Sysname-luser-manage-xyz] authorization-attribute user-role security-audit
This operation will delete all other roles of the user. Are you sure? [Y/N]:y
Related commands
display local-user
display user-group

bind-attribute

Use bind-attribute to configure binding attributes for a local user.
Use undo bind-attribute to remove binding attributes of a local user.
Syntax
bind-attribute { ip ip-address | location interface interface-type interface-number | mac
mac-address | vlan vlan-id } *
undo bind-attribute { ip | location | mac | vlan } *
Default
No binding attributes are configured for a local user.
Views
Local user view
Predefined user roles
network-admin
mdc-admin
Parameters
ip ip-address: Specifies the IP address to which the user is bound. This option applies only to 802.1X
users.
location interface interface-type interface-number: Specifies the interface to which the user is
bound. The interface-type argument represents the interface type, and the interface-number
argument represents the interface number. To pass authentication, the user must access the
network through the bound interface. This option applies only to LAN and portal users.
mac mac-address: Specifies the MAC address of the user in the format H-H-H. This option applies
only to LAN and portal users.
vlan vlan-id: Specifies the VLAN to which the user belongs. The vlan-id argument is in the range of 1
to 4094. This option applies only to LAN and portal users.
Usage guidelines
To perform local authentication of a user, the device matches the actual user attributes with the
configured binding attributes. If the user has a non-matching attribute or lacks a required attribute,
the user will fail authentication.
Binding attribute check takes effect on all access services. Configure the binding attributes for a user
based on the access services and make sure the device can obtain all attributes to be checked from
the user's packet. For example, you can configure an IP address binding for an 802.1X user,
because 802.1X authentication can include the user's IP address in the packet. However, you cannot
configure IP address bindings for MAC authentication users, because MAC authentication does not
use IP addresses.
The binding interface type must meet the requirements of the local user. Configure the binding
interface based on the service type of the user.
40

Advertisement

Table of Contents
loading

Table of Contents