H3C S5120-SI Series Command Reference Manual page 488

Hide thumbs Also See for S5120-SI Series:
Table of Contents

Advertisement

Default Level
2: System level
Parameters
keep-original: Sends the username to the RADIUS server as it is input.
with-domain: Includes the ISP domain name in the username sent to the RADIUS server.
without-domain: Excludes the ISP domain name from the username sent to the RADIUS server.
Description
Use the user-name-format command to specify the format of the username to be sent to a RADIUS
server.
By default, the ISP domain name is included in the username.
Note that:
A username is generally in the format of userid@isp-name, of which isp-name is used by the device
to determine the ISP domain to which a user belongs. Some earlier RADIUS servers, however,
cannot recognize a username including an ISP domain name. Before sending a username
including a domain name to such a RADIUS server, the device must remove the domain name.
This command is thus provided for you to decide whether to include a domain name in a username
to be sent to a RADIUS server.
If a RADIUS scheme defines that the username is sent without the ISP domain name, do not apply
the RADIUS scheme to more than one ISP domain, thus avoiding the confused situation where the
RADIUS server regards two users in different ISP domains but with the same user ID as one.
For 802.1X users using EAP authentication, the user-name-format command configured for a
RADIUS scheme does not take effect and the device does not change the usernames from clients
before forwarding them to the RADIUS server.
You can use this command to change the setting only when no user is using the RADIUS scheme.
Related commands: radius scheme.
Examples
# Specify the device to remove the domain name in the username sent to the RADIUS servers for the
RADIUS scheme radius1.
<Sysname> system-view
[Sysname] radius scheme radius1
[Sysname-radius-radius1] user-name-format without-domain
2-28

Advertisement

Table of Contents
loading

Table of Contents