Authorization Login - H3C MSR Series Command Reference Manual

Comware 7 security
Hide thumbs Also See for MSR Series:
Table of Contents

Advertisement

When the primary method is invalid, the device attempts to use the backup methods in sequence.
For example, the authorization lan-access radius-scheme radius-scheme-name local none
command specifies a primary RADIUS authorization method and two backup methods (local
authorization and no authorization). The device performs RADIUS authorization by default and
performs local authorization when the RADIUS server is invalid. The device does not perform
authorization when both of the previous methods are invalid.
Examples
# In ISP domain test, perform local authorization for LAN users.
<Sysname> system-view
[Sysname] domain test
[Sysname-isp-test] authorization lan-access local
# In ISP domain test, perform RADIUS authorization for LAN users based on scheme rd and use
local authorization as the backup.
<Sysname> system-view
[Sysname] domain test
[Sysname-isp-test] authorization lan-access radius-scheme rd local
Related commands
authorization default
local-user
radius scheme

authorization login

Use authorization login to specify authorization methods for login users.
Use undo authorization login to restore the default.
Syntax
In non-FIPS mode:
authorization
radius-scheme-name ] [ local ] [ none ] | local [ none ] | none | radius-scheme
radius-scheme-name [ hwtacacs-scheme hwtacacs-scheme-name ] [ local ] [ none ] }
undo authorization login
In FIPS mode:
authorization
radius-scheme-name ] [ local ] | local | radius-scheme radius-scheme-name [ hwtacacs-scheme
hwtacacs-scheme-name ] [ local ] }
undo authorization login
Default
The default authorization methods of the ISP domain are used for login users.
Views
ISP domain view
Predefined user roles
network-admin
login
{
hwtacacs-scheme
login
{
hwtacacs-scheme
hwtacacs-scheme-name
hwtacacs-scheme-name
34
[
radius-scheme
[
radius-scheme

Advertisement

Table of Contents
loading

Table of Contents