Tearing Down User Connections; Configuring A Nas Id-Vlan Binding - HP A5830 Series Configuration Manual

Security switch
Hide thumbs Also See for A5830 Series:
Table of Contents

Advertisement

To do...
5.
Specify the command
accounting method.
6.
Specify the accounting
method for LAN users.
7.
Specify the accounting
method for login users.
If you configure the accounting optional command, the limit on the number of local user connections is
not effective.
The accounting method specified with the accounting default command is for all types of users and has a
priority lower than that for a specific access type.
If you specify the radius-scheme radius-scheme-name local, hwtacacs-scheme hwtacacs-scheme-name
local option when you configure an accounting method, local accounting is the backup method and is
used only when the remote server is not available.
If you specify only the local or none keyword in an accounting method configuration command, the
switch has no backup accounting method and performs only local accounting or does not perform any
accounting.
Accounting is not supported for FTP services.

Tearing down user connections

To do...
1.
Enter system view.
2.
Tear down AAA user
connections.

Configuring a NAS ID-VLAN binding

The access locations of users can be identified by their access VLANs. In application scenarios where
identifying the access locations of users is required, configure NAS ID-VLAN bindings on the switch.
Then, when a user gets online, the switch obtains the NAS ID by the access VLAN of the user and sends
the NAS ID to the RADIUS server through the NAS-identifier attribute.
To configure a NAS ID-VLAN binding:
To do...
1.
Enter system view.
Use the command...
accounting command hwtacacs-
scheme hwtacacs-scheme-name
accounting lan-access { local | none |
radius-scheme radius-scheme-name [
local | none ] }
accounting login { hwtacacs-scheme
hwtacacs-scheme-name [ local ] |
local | none | radius-scheme radius-
scheme-name [ local ] }
Use the command...
system-view
cut connection { access-type { dot1x | mac-
authentication } | all | domain isp-name |
interface interface-type interface-number | ip ip-
address | mac mac-address | ucibindex ucib-
index | user-name user-name | vlan vlan-id } [
slot slot-number ]
Use the command...
system-view
42
Remarks
Optional.
The default accounting method
is used by default.
Optional.
The default accounting method
is used by default.
Optional.
The default accounting method
is used by default.
Remarks
Required
Applies only to LAN
user connections
Remarks

Advertisement

Table of Contents
loading

Table of Contents