Configuring Separate Aaa Schemes; Configuration Example For Separate Aaa Schemes - 3Com 5500-SI Configuration Manual

5500 series
Hide thumbs Also See for 5500-SI:
Table of Contents

Advertisement

414
C
21: 802.1
HAPTER
Configuring Separate
AAA Schemes
Configuration Example
for Separate AAA
Schemes
C
X
ONFIGURATION
Table 443 Configure separate AAA schemes
Operation
Enter system view
Create an ISP domain or
enter an existing ISP domain
view
Configure an authentication
scheme for the ISP domain
Allow users in current ISP
domain to use network
services without being
authorized
Configure an accounting
scheme for the ISP domain
If a bound AAA scheme (that is, the authentication, authorization and accounting are
bound in one scheme) is configured as well as the separate authentication,
authorization and accounting schemes, the separate ones will be adopted in
precedence.
RADIUS scheme and local scheme do not support the separation of authentication
and authorization. Therefore, pay attention when you perform authentication and
authorization configuration: when the scheme radius-scheme or scheme local
command is executed and the authentication command is not executed, the
authorization information returned from the RADIUS or local scheme will still take
effect even if the authorization none command is executed.
Network requirements
A RADIUS server with IP address 10.110.91.164 is connected to the switch. This
server will be used as an authentication server.
On the switch, set the shared key it uses to exchange packets with the RADIUS server
to "expert".
Configure the RADIUS scheme radius as both the authentication and accounting
schemes of the ISP domain cams, and allow users in this ISP domain to use network
services without being authorized.
Command
system-view
domain isp-name
authentication {
radius-scheme
radius-scheme-name [ local
] | local | none }
authorization none
accounting { none |
radius-scheme
radius-scheme-name }
Description
Required
Optional
By default, no separate
authentication scheme is configured.
Optional
By default, no separate authorization
scheme is configured.
Optional
By default, no separate accounting
scheme is configured.

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

5500-ei5500g-ei

Table of Contents