Configuring Aaa Methods For Isp Domains; Creating An Isp Domain - HP 6600 Security Configuration Manual

Table of Contents

Advertisement

Configuring AAA methods for ISP domains

By default, the device uses local (default) AAA methods for users in an ISP domain. To use other AAA
methods for them, configure the device to reference existing AAA schemes for the ISP domain. For
information about configuring AAA schemes, see
HWTACACS
To use local authentication for users in an ISP domain, first configure local user accounts on the device
(see
"Configuring local user

Creating an ISP domain

In a networking scenario with multiple ISPs, the device can connect users of different ISPs. Different ISP
users can have different user attributes (such as username and password structures), different service
types, and different rights. To manage these ISP users, you need to create ISP domains and then
configure AAA methods and domain attributes for each ISP domain.
The device can accommodate up to 16 ISP domains, including the system predefined ISP domain system.
You can specify one ISP domain as the default domain.
On the device, each user belongs to an ISP domain. If a user provides no ISP domain name at login, the
device considers the user belongs to the default ISP domain.
The device chooses an authentication domain for each user in the following order:
The authentication domain specified for the access module
The ISP domain in the username
The default ISP domain of the device
The ISP domain specified for users with unknown domain names
If all the domains are unavailable, user authentication will fail.
NOTE:
Support for the authentication domain configuration depends on the access module. You can specify an
authentication domain for 802.1X, portal, or MAC address authentication.
To create an ISP domain:
Step
1.
Enter system view.
Create an ISP domain and
2.
enter ISP domain view.
3.
Return to system view.
4.
Specify the default ISP
domain.
5.
Specify an ISP domain for
users with unknown domain
names.
schemes."
attributes").
Command
system-view
domain isp-name
quit
domain default enable
isp-name
domain if-unknown
isp-name
"Configuring RADIUS
Remarks
N/A
N/A
N/A
Optional.
By default, the default ISP domain is the
system predefined ISP domain system.
Optional.
By default, no ISP domain is specified for
users with unknown domain names.
45
schemes" and
"Configuring

Advertisement

Table of Contents
loading

This manual is also suitable for:

Hsr6600

Table of Contents