access device can obtain the NAS ID by the access VLAN of the user and then send the NAS ID to the
RADIUS server through the NAS-identifier attribute.
Follow these steps to configure a NAS ID-VLAN binding:
To do...
Enter system view
Create a NAS ID profile and
enter NAS ID profile view
Configure a NAS ID-VLAN
binding
Displaying and Maintaining AAA
To do...
Display the configuration information
of a specified ISP domain or all ISP
domains
Display information about specified
or all user connections
Display information about specified
or all local users on
Display configuration information
about a specified user group or all
user groups
Configuring RADIUS
The RADIUS protocol is configured on a per scheme basis. After creating a RADIUS scheme, you need
to configure the IP addresses and UDP ports of the RADIUS servers for the scheme. The servers
include authentication/authorization servers and accounting servers, or primary servers and secondary
servers. In other words, the attributes of a RADIUS scheme mainly include IP addresses of primary and
secondary servers, shared key, and RADIUS server type.
Actually, the RADIUS protocol configurations only set the parameters necessary for the information
interaction between a NAS and a RADIUS server. For these settings to take effect, you must reference
the RADIUS scheme containing those settings in ISP domain view. For information about the
commands for referencing a scheme, refer to
Use the command...
system-view
aaa nas-id profile
profile-name
nas-id nas-identifier bind vlan
vlan-id
Use the command...
display domain [ isp-name ]
display connection [ domain
isp-name | ucibindex ucib-index |
user-name user-name ]
display local-user [ idle-cut
{ disable | enable } | service-type
{ ftp | lan-access | ssh | telnet |
terminal } | state { active | block } |
user-name user-name | vlan
vlan-id ]
display user-group [ group-name ]
Configuring
AAA.
1-18
Remarks
—
Required
Required
By default, no NAS ID-VLAN
binding exists.
Remarks
Available in any view
Available in any view
Available in any view
Available in any view