Configuring Aaa Schemes; Configuring Local Users - HP 6600 Security Configuration Manual

Table of Contents

Advertisement

Table 4 AAA configuration task list
Task
Configuring AAA
schemes
Configuring AAA
methods for ISP domains
Tearing down user connections
Configuring a NAS ID-VLAN binding
Specifying the device ID used in stateful failover mode
NOTE:
To use AAA methods to control access of login users, you must configure the user interfaces to use AAA by
using the authentication-mode command. For more information, see

Configuring AAA schemes

Configuring local users

To implement local AAA, you must create local users and configure user attributes on the device. The
local users and attributes are stored in the local user database on the device. A local user is uniquely
identified by a username. Configurable local user attributes are as follows:
Service type.
Services that the user can use. Local authentication checks the service types of a local user. If none
of the service types is available, the user cannot pass authentication.
Service types include DVPN, FTP, LAN access, portal, PPP, SSH, Telnet, terminal, and Web.
User state.
Indicates whether or not a local user can request network services. There are two user states: active
and blocked. A user in active state can request network services, but a user in blocked state
cannot.
Maximum number of users using the same local user account:
Indicates how many users can use the same local user account for local authentication.
Validity time and expiration time.
Indicates the validity time and expiration time of a local user account. A user must use a valid local
user account to pass local authentication. When some users need to access the network
temporarily, you can create a guest account and specify a validity time and an expiration time for
the account to control the validity of the account.
Configuring local users
Configuring RADIUS schemes
Configuring HWTACACS schemes
Creating an ISP domain
Configuring ISP domain attributes
Configuring authentication methods for an ISP domain
Configuring authorization methods for an ISP domain
Configuring accounting methods for an ISP domain
21
Remarks
Required.
Complete at least
one task.
Required.
Optional.
Required.
Complete at least
one task.
Optional.
Optional.
Optional.
Fundamentals Configuration Guide
.

Advertisement

Table of Contents
loading

This manual is also suitable for:

Hsr6600

Table of Contents