Huawei Quidway S3100 Series Operation Manual page 245

Table of Contents

Advertisement

Operation Manual – AAA&RADIUS
Quidway S3100 Series Ethernet Switches
II. Configuring separate AAA schemes
You can use the authentication, authorization, and accounting commands to
specify a scheme for each of the three AAA functions (authentication, authorization and
accounting) respectively. The following gives the implementations of this separate way
for the services supported by AAA.
For terminal users
Authentication: RADIUS, local, RADIUS-local or none.
Authorization: none.
Accounting: RADIUS or none.
You can configure combined authentication, authorization and accounting schemes by
using the above implementations.
For FTP users
Only authentication is supported for FTP users.
Authentication: RADIUS, local, or RADIUS-local.
Perform the following configuration in ISP domain view.
Table 1-7 Configure separate AAA schemes
Operation
Enter system view
Create an ISP domain or
enter the view of an
existing ISP domain
Configure
authentication
for the ISP domain
Allow users in current
ISP domain to access
the
network
without being authorized
Configure an accounting
scheme
domain
system-view
domain isp-name
authentication
an
{
scheme
radius-scheme-name [ local ] |
local | none }
authorization none
services
accounting
for
the
ISP
radius-scheme
radius-scheme-name }
Huawei Technologies Proprietary
Chapter 1 AAA&RADIUS Configuration
Command
radius-scheme
{
none
1-13
Description
Required
Optional
By
default,
no
separate
authentication
scheme
is
configured.
Optional
By
default,
no
separate
authorization
scheme
is
configured.
Optional
|
By
default,
no
separate
accounting scheme
is configured.

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents