Configuration Prerequisites; Creating An Isp Domain; Configuring Isp Domain Attributes - HP 5120 SI Series Security Configuration Manual

Hide thumbs Also See for 5120 SI Series:
Table of Contents

Advertisement

Configuration prerequisites

To use local authentication for users in an ISP domain, configure local user accounts (see
local user
attributes") on the access device.
To use remote authentication, authorization, and accounting, create the required RADIUS and
HWTACACS schemes as described in
schemes."

Creating an ISP domain

In a networking scenario with multiple ISPs, an access device may connect users of different ISPs.
Because users of different ISPs may have different user attributes (for example, different username and
password structure, service type, and rights), you must configure ISP domains to distinguish the users and
configure different AAA methods for the ISP domains.
On a NAS, each user belongs to an ISP domain. A NAS can accommodate up to 16 ISP domains,
including the factory default ISP domain, which is named system. If a user does not provide the ISP
domain name at login, the system considers that the user belongs to the default ISP domain.
Follow these steps to create an ISP domain:
To do...
Enter system view
Create an ISP domain and enter
ISP domain view
Return to system view
Specify the default ISP domain
NOTE:
To delete the default ISP domain, you must change it to a non-default ISP domain (with the undo domain
default enable command) first.

Configuring ISP domain attributes

Follow these steps to configure ISP domain attributes:
To do...
Enter system view
Enter ISP domain view
Place the ISP domain to the state of
active or blocked
"Configuring RADIUS
Use the command...
system-view
domain isp-name
quit
domain default enable
isp-name
Use the command...
system-view
domain isp-name
state { active | block }
37
schemes" and
"Configuring HWTACACS
Remarks
Required
Optional
By default, the default ISP domain is the
factory default ISP domain system.
Remarks
Optional
By default, an ISP domain is in the
active state, and users in the domain
can request network services.
"Configuring

Advertisement

Table of Contents
loading

Table of Contents