H3C S6550X-HI Series Command Reference Manual page 2299

Table of Contents

Advertisement

Syntax
client-authentication xauth
undo client-authentication xauth
Default
Client authentication is disabled.
Views
IKE profile view
Predefined user roles
network-admin
Parameters
: Uses Extended Authentication within ISAKMP/Oakley (XAUTH) for authentication.
xauth
Usage guidelines
Client authentication enables an IPsec gateway to authenticate remote users through a RADIUS
server in IKE negotiation. Remote users who provide the correct username and password pass the
authentication and continue with the IKE negotiation. This feature simplifies the configuration on the
IPsec gateway and ensures the validity of the remote users. If you do not use this feature, you must
configure an IPsec policy and an authentication password for each remote user.
Examples
# Enable XAUTH client authentication.
<Sysname> system-view
[Sysname] ike profile test
[Sysname-ike-profile-test] client-authentication xauth
Related commands
local-user
client-authentication xauth user
Use
client-authentication xauth user
authentication.
Use
undo client-authentication xauth user
Syntax
client-authentication xauth user username password { cipher | simple }
string
undo client-authentication xauth user
Default
The username and password for client authentication are not specified.
Views
IKE profile view
Predefined user roles
network-admin
(User Access and Authentication Command Reference)
to specify the username and password for client
to restore the default.
5

Advertisement

Table of Contents
loading

Table of Contents