H3C SR8800-F Configuration Manual page 7

Comware 7 user access
Hide thumbs Also See for SR8800-F:
Table of Contents

Advertisement

Specifying the HWTACACS accounting servers ······································································· 44
Specifying the shared keys for secure HWTACACS communication ············································· 44
Specifying an MPLS L3VPN instance for the scheme ································································ 45
Setting the username format and traffic statistics units ······························································ 45
Configuring HWTACACS stop-accounting packet buffering ························································ 46
Specifying the source IP address for outgoing HWTACACS packets ············································ 46
Setting HWTACACS timers ································································································· 47
Display and maintenance commands for HWTACACS ······························································ 48
Configuring LDAP ···················································································································· 49
LDAP tasks at a glance ······································································································ 49
Creating an LDAP server ···································································································· 49
Configuring the IP address of the LDAP server ········································································ 49
Specifying the LDAP version ································································································ 50
Setting the LDAP server timeout period ·················································································· 50
Configuring administrator attributes ······················································································· 50
Configuring LDAP user attributes ·························································································· 51
Configuring an LDAP attribute map ······················································································· 52
Creating an LDAP scheme ·································································································· 52
Specifying the LDAP authentication server·············································································· 53
Specifying the LDAP authorization server ··············································································· 53
Specifying an LDAP attribute map for LDAP authorization ·························································· 53
Display and maintenance commands for LDAP ········································································ 53
Configuring AAA methods for ISP domains ···················································································· 54
Creating an ISP domain ······································································································ 54
Configuring ISP domain attributes ························································································· 55
Configuring authentication methods for an ISP domain ······························································ 58
Configuring authorization methods for an ISP domain ······························································· 60
Configuring accounting methods for an ISP domain ·································································· 62
Display and maintenance commands for ISP domains ······························································ 64
Setting the maximum number of concurrent login users···································································· 65
Configuring the local bill cache feature ························································································· 65
About local bill cache ········································································································· 65
Procedure ························································································································ 65
Display and maintenance commands for local bill cache ···························································· 66
Configuring a NAS-ID ··············································································································· 66
About NAS-IDs ················································································································· 66
Configuring a NAS-ID profile ································································································ 66
Setting the NAS-ID on an interface ························································································ 67
Setting the NAS-ID in an ISP domain ····················································································· 67
Configuring the device ID ··········································································································· 68
AAA configuration examples ······································································································· 68
Example: Configuring local authentication and authorization for SSH users ··································· 71
Example: Configuring AAA for SSH users by an HWTACACS server ············································ 72
Example: Configuring authentication for SSH users by an LDAP server ········································ 73
Example: Configuring AAA for PPP users by an HWTACACS server ············································ 78
Troubleshooting RADIUS ··········································································································· 79
RADIUS authentication failure ······························································································ 79
RADIUS packet delivery failure ···························································································· 80
RADIUS accounting error ···································································································· 80
Troubleshooting HWTACACS ····································································································· 81
Troubleshooting LDAP ·············································································································· 81
LDAP authentication failure ································································································· 81
Appendixes ···························································································································· 82
Appendix A Commonly used RADIUS attributes ······································································· 82
Appendix B Descriptions for commonly used standard RADIUS attributes ····································· 83
Appendix C RADIUS subattributes (vendor ID 25506) ······························································· 85
DHCP overview ············································································· 88
DHCP network model ··············································································································· 88
DHCP address allocation ··········································································································· 88
Allocation mechanisms ······································································································· 88
ii
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Advertisement

Table of Contents
loading

Table of Contents