Configuring Radius Schemes - H3C S5120-HI Security Configuration Manual

Hide thumbs Also See for S5120-HI:
Table of Contents

Advertisement

Step
3.
Configure password control
attributes for the user group.
4.
Configure the authorization
attributes for the user group.
5.
Set the guest attribute for the
user group.
Displaying and maintaining local users and local user groups
Task
Display local user
information
Display the user group
configuration information.

Configuring RADIUS schemes

A RADIUS scheme specifies the RADIUS servers that the switch can cooperate with and defines a set of
parameters that the switch uses to exchange information with the RADIUS servers. There may be
authentication/authorization servers and accounting servers, or primary servers and secondary servers.
The parameters include the IP addresses of the servers, the shared keys, and the RADIUS server type.
RADIUS scheme configuration task list
Task
Creating a RADIUS scheme
Specifying the RADIUS authentication/authorization servers
Command
Set the password aging time:
password-control aging
aging-time
Set the minimum password
length:
password-control length length
Configure the password
composition policy:
password-control composition
type-number type-number
[ type-length type-length ]
authorization-attribute { acl
acl-number | idle-cut minute | level
level | user-profile profile-name |
vlan vlan-id | work-directory
directory-name } *
group-attribute allow-guest
Command
display local-user [ idle-cut { disable | enable } |
service-type { ftp | lan-access | portal | ssh | telnet
| terminal | web } | state { active | block } |
user-name user-name | vlan vlan-id ] [ slot
slot-number ] [ | { begin | exclude | include }
regular-expression ]
display user-group [ group-name ] [ | { begin |
exclude | include } regular-expression ]
20
Remarks
Optional.
By default, the user group uses
global password control attribute
settings.
For more information about
password control attributes
configuration commands, see
Security Command Reference.
Optional.
By default, no authorization
attribute is configured for a user
group.
Optional.
By default, the guest attribute is not
set for a user group, and guest
users created by a guest manager
through the Web interface cannot
join the group.
Remarks
Available in any view
Available in any view
Remarks
Required
Required

Advertisement

Table of Contents
loading

Table of Contents