Huawei Quidway S3100 Series Operation Manual page 244

Table of Contents

Advertisement

Operation Manual – AAA&RADIUS
Quidway S3100 Series Ethernet Switches
implemented by the RADIUS server specified in the RADIUS scheme. In this way, you
can specify only one scheme to implement all the three AAA functions and do not need
to specify different schemes for authentication, authorization and accounting
respectively.
Table 1-6 Configure a bound AAA scheme
Operation
Enter system view
Create an ISP domain
or enter the view of an
existing ISP domain
Configure
scheme for the ISP
domain
Configure an RADIUS
scheme for the ISP
domain
Caution:
You can execute the scheme command with the radius-scheme-name argument to
adopt an already configured RADIUS scheme to implement all the three AAA
functions. If you adopt the local scheme, only the authentication and authorization
functions are implemented, the accounting function cannot be implemented.
If you execute the scheme radius-scheme radius-scheme-name local command,
the local scheme becomes the secondary scheme in case the RADIUS server does
not response normally. That is, if the communication between the switch and the
RADIUS server is normal, no local authentication is performed; otherwise, local
authentication is performed.
If you execute the scheme local command, the local scheme is adopted as the
primary scheme. In this case, only local authentication is performed, no RADIUS
authentication is performed.
If you execute the scheme none command, no authentication is performed.
system-view
domain isp-name
an
AAA
scheme
radius-scheme
radius-scheme-name [ local ] }
radius-scheme
radius-scheme-name
Huawei Technologies Proprietary
1-12
Chapter 1 AAA&RADIUS Configuration
Command
{
local
|
none
Description
Required
Required
|
By default, the ISP
domain uses the
local
AAA
scheme.
Optional
This command has
the same effect as
the
scheme
radius-scheme
command.

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents