Scheme Login - H3C s3100 series Command Manual

Hide thumbs Also See for s3100 series:
Table of Contents

Advertisement

scheme login

Syntax
scheme login { local | none | radius-scheme radius-scheme-name [ local ] | hwtacacs-scheme
hwtacacs-scheme-name [ local ] }
undo scheme login
View
ISP domain view
Parameters
radius-scheme-name: Name of a RADIUS scheme, a string of up to 32 characters.
local: Specifies to use local authentication.
none: Specifies not to perform authentication.
hwtacacs-scheme-name: Name of a HWTACACS scheme, a string of up to 32 characters.
Description
Use the scheme login command to configure a combined AAA scheme for login users.
Use the undo scheme login command to restore the default.
By default, the local AAA scheme is used.
Note that:
When you use the scheme login command to reference a RADIUS scheme in the current ISP
domain, the referenced RADIUS scheme must already exist.
If you use the scheme login radius-scheme radius-scheme-name local command, the local
scheme is used as the secondary scheme in case no RADIUS server is available. That is, if the
communication between the switch and a RADIUS server is normal, remote authentication is
performed; otherwise, local authentication is performed.
If you execute the scheme login hwtacacs-scheme hwtacacs-scheme-name local command,
the local scheme is used as the secondary scheme in case no TACACS server is available. That is,
if the communication between the switch and a TACACS server is normal, remote authentication is
performed; if the TACACS server is not reachable or there is a key error, NAS IP error, or
authentication failure, local authentication is performed.
If you execute the scheme login local or scheme login none command to use local or none as
the primary scheme, local authentication is performed or no authentication is performed. In this
case, no secondary scheme can be specified and therefore no scheme switching will occur.
Related commands: scheme.
Examples
# Configure the default ISP domain system to use RADIUS scheme radius1 for login users and use
local authentication as the backup.
<Sysname> system-view
System View: return to User View with Ctrl+Z.
[Sysname] domain system
[Sysname-isp-aabbcc.net] scheme login radius-scheme radius1 local
1-28

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents