Authorization-Attribute - H3C S5120-SI Series Command Reference Manual

Hide thumbs Also See for S5120-SI Series:
Table of Contents

Advertisement

Default Level
2: System level
Parameters
local: Performs local authorization.
none: Does not perform any authorization. In this case, an authenticated user is automatically
authorized with the default rights.
radius-scheme radius-scheme-name: Specifies a RADIUS scheme by its name, which is a string of 1
to 32 characters.
Description
Use the authorization login command to configure the authorization method for login users.
Use the undo authorization login command to restore the default.
By default, the default authorization method is used for login users.
Note that:
The RADIUS scheme specified for the current ISP domain must have been configured.
RADIUS authorization is special in that it takes effect only when the RADIUS authorization scheme
is the same as the RADIUS authentication scheme. If the RADIUS authorization scheme is
different from the RADIUS authentication scheme, RADIUS authorization will fail.
Related commands: authorization default, radius scheme.
Examples
# Configure the default ISP domain system to use local authorization for login users.
<Sysname> system-view
[Sysname] domain system
[Sysname-isp-system] authorization login local
# Configure ISP domain test to use RADIUS authorization scheme rd for login users and use local
authorization as the backup.
<Sysname> system-view
[Sysname] domain test
[Sysname-isp-test] authorization login radius-scheme rd local

authorization-attribute

Syntax
authorization-attribute { acl acl-number | callback-number callback-number | idle-cut minute | level
level | user-profile profile-name | vlan vlan-id | work-directory directory-name } *
undo authorization-attribute { acl | callback-number | idle-cut | level | user-profile | vlan |
work-directory } *
View
Local user view, user group view
1-12

Advertisement

Table of Contents
loading

Table of Contents