H3C S6550X-HI Series Command Reference Manual page 2335

Table of Contents

Advertisement

IKEv2 commands
aaa authorization
Use
aaa authorization
Use
undo aaa authorization
Syntax
aaa authorization domain domain-name username user-name
undo aaa authorization
Default
IKEv2 AAA authorization is disabled.
Views
IKEv2 profile view
Predefined user roles
network-admin
Parameters
domain domain-name
ISP domain name is a case-insensitive string of 1 to 255 characters and must meet the following
requirements:
The name cannot contain a forward slash (/), backslash (\), vertical bar (|), quotation mark ("),
colon (:), asterisk (*), question mark (?), left angle bracket (<), right angle bracket (>), or an at
sign (@).
The name cannot be d, de, def, defa, defau, defaul, default, i, if, if-, if-u, if-un, if-unk, if-unkn,
if-unkno, if-unknow, or if-unknown.
username user-name
username is a case-sensitive string of 1 to 55 characters and must meet the following requirements:
The username cannot contain the domain name.
The username cannot contain a forward slash (/), backslash (\), vertical bar (|), colon (:),
asterisk (*), question mark (?), left angle bracket (<), right angle bracket (>), or an at sign (@).
The username cannot be a, al, or all.
Usage guidelines
The AAA authorization feature enables IKEv2 to request authorization attributes, such as the IKEv2
address pool, from AAA.
IKEv2 uses the ISP domain and username to request authorization attributes. AAA uses the
authorization settings in the ISP domain to request the user's authorization attributes from the
remote AAA server or the local user database. After IKEv2 passes the username authentication, it
obtains the authorization attributes.
This feature is applicable when AAA is used to centrally manage and deploy authorization attributes.
Examples
# Create an IKEv2 profile named profile1.
<Sysname> system-view
[Sysname] ikev2 profile profile1
to enable IKEv2 AAA authorization.
to disable IKEv2 AAA authorization.
: Specifies the ISP domain used for requesting authorization attributes. The
: Specifies the username used for requesting authorization attributes. The
1

Advertisement

Table of Contents
loading

Table of Contents