Configuring Aaa Methods For Isp Domains; Configuration Prerequisites - HP FlexNetwork 10500 Series Security Configuration Manual

Hide thumbs Also See for FlexNetwork 10500 Series:
Table of Contents

Advertisement

Step
7.
(Optional.) Specify the user
object class.
Creating an LDAP scheme
You can configure up to 16 LDAP schemes. An LDAP scheme can be referenced by multiple ISP
domains.
To create an LDAP scheme:
Step
1.
Enter system view.
2.
Create an LDAP scheme
and enter LDAP scheme
view.
Specifying the LDAP authentication server
Step
1.
Enter system view.
2.
Enter LDAP scheme view.
3.
Specify the LDAP
authentication server.
Displaying and maintaining LDAP
Execute display commands in any view.
Task
Display the configuration of LDAP schemes.

Configuring AAA methods for ISP domains

You configure AAA methods for an ISP domain by referencing configured AAA schemes in ISP
domain view. Each ISP domain has a set of system-defined AAA methods, which are local
authentication, local authorization, and local accounting. If you do not configure any AAA methods
for an ISP domain, the device uses the system-defined AAA methods for users in the domain.
AAA is available to login users after you enable scheme authentication for the users. For more
information about the login authentication modes, see Fundamentals Configuration Guide.

Configuration prerequisites

To use local authentication for users in an ISP domain, configure local user accounts on the device
first. See
"Configuring local user
To use remote authentication, authorization, and accounting, create the required RADIUS,
HWTACACS, or LDAP schemes. For more information about the scheme configuration, see
Command
user-parameters
user-object-class
object-class-name
Command
system-view
ldap scheme
ldap-scheme-name
Command
system-view
ldap scheme ldap-scheme-name
authentication-server
server-name
attributes."
42
Remarks
By default, no user object is
specified, and the default user
object class on the LDAP server is
used.
Remarks
N/A
By default, no LDAP scheme is defined.
Remarks
N/A
N/A
By default, no LDAP authentication
server is specified.
Command
display ldap scheme [ scheme-name ]

Advertisement

Table of Contents
loading

Table of Contents