H3C S6550X-HI Series Command Reference Manual page 2295

Table of Contents

Advertisement

IKE commands
aaa authorization
Use
aaa authorization
Use
undo aaa authorization
Syntax
aaa authorization domain domain-name username user-name
undo aaa authorization
Default
IKE AAA authorization is disabled.
Views
IKE profile view
Predefined user roles
network-admin
Parameters
domain domain-name
ISP domain name is a case-insensitive string of 1 to 255 characters and must meet the following
requirements:
The name cannot contain a forward slash (/), backslash (\), vertical bar (|), quotation mark ("),
colon (:), asterisk (*), question mark (?), left angle bracket (<), right angle bracket (>), or an at
sign (@).
The name cannot be d, de, def, defa, defau, defaul, default, i, if, if-, if-u, if-un, if-unk, if-unkn,
if-unkno, if-unknow, or if-unknown.
username
username is a case-sensitive string of 1 to 55 characters and must meet the following requirements:
The username cannot contain the domain name.
The username cannot contain a forward slash (/), backslash (\), vertical bar (|), colon (:),
asterisk (*), question mark (?), left angle bracket (<), right angle bracket (>), or an at sign (@).
The username cannot be a, al, or all.
Usage guidelines
The AAA authorization feature enables IKE to request authorization attributes, such as the IKE IPv4
address pool, from AAA.
IKE uses the ISP domain and username to request authorization attributes. AAA uses the
authorization settings in the ISP domain to request the user's authorization attributes from the
remote AAA server or the local user database. After IKE passes the username authentication, it
obtains the authorization attributes.
This feature is applicable when AAA is used to centrally manage and deploy authorization attributes.
Examples
# Create IKE profile profile1.
<Sysname> system-view
[Sysname] ike profile profile1
to enable IKE AAA authorization.
: Specifies the ISP domain used for requesting authorization attributes. The
: Specifies the username used for requesting authorization attributes. The
user-name
to disable IKE AAA authorization.
1

Advertisement

Table of Contents
loading

Table of Contents