H3C S6812 Series Command Reference Manual page 1653

Hide thumbs Also See for S6812 Series:
Table of Contents

Advertisement

Parameters
hwtacacs-scheme hwtacacs-scheme-name: Specifies an HWTACACS scheme by its name, a
case-insensitive string of 1 to 32 characters.
ldap-scheme ldap-scheme-name: Specifies an LDAP scheme by its name, a case-insensitive string
of 1 to 32 characters.
local: Performs local authentication.
none: Does not perform authentication.
radius-scheme radius-scheme-name: Specifies a RADIUS scheme by its name, a case-insensitive
string of 1 to 32 characters.
Usage guidelines
The default authentication method is used for all users who support this method and do not have an
authentication method configured.
You can specify one primary default authentication method and multiple backup default
authentication methods.
When the primary method is invalid, the device attempts to use the backup methods in sequence.
For example, the authentication default radius-scheme radius-scheme-name local none
command specifies a primary default RADIUS authentication method and two backup methods
(local authentication and no authentication). The device performs RADIUS authentication by default
and performs local authentication when the RADIUS server is invalid. The device does not perform
authentication when both of the previous methods are invalid.
Examples
# In ISP domain test, use RADIUS scheme rd as the primary default authentication method and use
local authentication as the backup.
<Sysname> system-view
[Sysname] domain test
[Sysname-isp-test] authentication default radius-scheme rd local
Related commands
hwtacacs scheme
ldap scheme
local-user
radius scheme
authentication lan-access
Use authentication lan-access to configure the authentication method for LAN users.
Use undo authentication lan-access to restore the default.
Syntax
In non-FIPS mode:
authentication lan-access { ldap-scheme ldap-scheme-name [ local ] [ none ] | local [ none ] |
none | radius-scheme radius-scheme-name [ local ] [ none ] }
undo authentication lan-access
In FIPS mode:
authentication lan-access { ldap-scheme ldap-scheme-name [ local ] | local | radius-scheme
radius-scheme-name [ local ] }
undo authentication lan-access
12

Advertisement

Table of Contents
loading

This manual is also suitable for:

S6813 seriesS5150-ei

Table of Contents