User-Name-Format (Radius Scheme View) - HP A5500 EI Command Reference Manual

Hide thumbs Also See for A5500 EI:
Table of Contents

Advertisement

The maximum number of RADIUS packet transmission attempts multiplied by the RADIUS server response
timeout period cannot be greater than 75.
Related commands: radius scheme and retry.
Examples
# Set the RADIUS server response timeout timer to 5 seconds for RADIUS scheme radius1.
<Sysname> system-view
[Sysname] radius scheme radius1
[Sysname-radius-radius1] timer response-timeout 5

user-name-format (RADIUS scheme view)

Syntax
user-name-format { keep-original | with-domain | without-domain }
View
RADIUS scheme view
Default level
2: System level
Parameters
keep-original: Sends the username to the RADIUS server as it is input.
with-domain: Includes the ISP domain name in the username sent to the RADIUS server.
without-domain: Excludes the ISP domain name from the username sent to the RADIUS server.
Description
Use the user-name-format command to specify the format of the username to be sent to a RADIUS server.
By default, the ISP domain name is included in the username.
A username is generally in the format userid@isp-name, of which isp-name is used by the device to
determine the ISP domain to which a user belongs. Some earlier RADIUS servers, however, cannot
recognize a username including an ISP domain name. Before sending a username including a domain
name to such a RADIUS server, the device must remove the domain name. This command allows you to
specify whether to include a domain name in a username to be sent to a RADIUS server.
If a RADIUS scheme defines that the username is sent without the ISP domain name, do not apply the
RADIUS scheme to more than one ISP domain, avoiding the confused situation where the RADIUS server
regards two users in different ISP domains but with the same userid as one.
For 802.1X users using EAP authentication, the user-name-format command configured for a RADIUS
scheme does not take effect and the device does not change the usernames from clients before
forwarding them to the RADIUS server.
If the RADIUS scheme is for roaming wireless users, specify the keep-original keyword. Otherwise,
authentication of the wireless users may fail.
Related commands: radius scheme.
Examples
# Specify the device to remove the domain name in the username sent to the RADIUS servers for the
RADIUS scheme radius1.
<Sysname> system-view
70

Advertisement

Table of Contents
loading

This manual is also suitable for:

A5500 si

Table of Contents