Authentication Ike - H3C MSR Series Command Reference Manual

Comware 7 security
Hide thumbs Also See for MSR Series:
Table of Contents

Advertisement

When the primary method is invalid, the device attempts to use the backup methods in sequence.
For example, the authentication default radius-scheme radius-scheme-name local none
command specifies a primary default RADIUS authentication method and two backup methods
(local authentication and no authentication). The device performs RADIUS authentication by default
and performs local authentication when the RADIUS server is invalid. The device does not perform
authentication when both of the previous methods are invalid.
Examples
# In ISP domain test, use RADIUS scheme rd as the primary default authentication method and use
local authentication as the backup.
<Sysname> system-view
[Sysname] domain test
[Sysname-isp-test] authentication default radius-scheme rd local
Related commands
hwtacacs scheme
ldap scheme
local-user
radius scheme

authentication ike

Use authentication ike to specify extended authentication methods for IKE users.
Use undo authentication ike to restore the default.
Syntax
In non-FIPS mode:
authentication ike { local [ none ] | none | radius-scheme radius-scheme-name [ local ] [ none ] }
undo authentication ike
In FIPS mode:
authentication ike { local | radius-scheme radius-scheme-name [ local ] }
undo authentication ike
Default
The default authentication methods of the ISP domain are used for IKE extended authentication.
Views
ISP domain view
Predefined user roles
network-admin
Parameters
local: Performs local authentication.
none: Does not perform authentication.
radius-scheme radius-scheme-name: Specifies a RADIUS scheme by its name, a case-insensitive
string of 1 to 32 characters.
Usage guidelines
You can specify one primary authentication method and multiple backup authentication methods.
18

Advertisement

Table of Contents
loading

Table of Contents