HP 6125XLG Command Reference Manual page 21

Blade switch security command reference
Table of Contents

Advertisement

authorization default { hwtacacs-scheme hwtacacs-scheme-name [ radius-scheme radius-scheme-name ]
[ local ] [ none ] | local [ none ] | none | radius-scheme radius-scheme-name [ hwtacacs-scheme
hwtacacs-scheme-name ] [ local ] [ none ] }
undo authorization default
In FIPS mode:
authorization default { hwtacacs-scheme hwtacacs-scheme-name [ radius-scheme radius-scheme-name ]
[ local ] | local | radius-scheme radius-scheme-name [ hwtacacs-scheme hwtacacs-scheme-name ]
[ local ] }
undo authorization default
Default
The default authorization method of an ISP domain is local.
Views
ISP domain view
Predefined user roles
network-admin
Parameters
hwtacacs-scheme hwtacacs-scheme-name: Specifies an HWTACACS scheme by its name, a
case-insensitive string of 1 to 32 characters.
local: Performs local authorization.
none: Does not perform authorization. After passing authentication, non-login users can access the
network, FTP users use the root directory of the device as the work directory but cannot access it, and
other login users get the default user role. For more information about the default user role, see
Fundamentals Configuration Guide.
radius-scheme radius-scheme-name: Specifies a RADIUS scheme by its name, a case-insensitive string of
1 to 32 characters.
Usage guidelines
The default authorization method is used for all users who support this method and do not have a specific
authorization method are configured.
The RADIUS authorization configuration takes effect only when the authentication method and
authorization method of the ISP domain use the same RADIUS scheme.
You can specify one authorization method and multiple backup authorization methods. When the default
authorization method is invalid, the device attempts to use the backup authorization methods in sequence.
For example, the authorization default radius-scheme radius-scheme-name local none command
specifies the default RADIUS authorization method and two backup authorization methods, local
authorization and no authorization. With this command, the device performs RADIUS authorization by
default, performs local authorization when the RADIUS server is invalid, and does not perform
authorization when both of the previous methods are invalid.
Examples
# Configure the default authorization method for ISP domain test to use RADIUS scheme rd for user
authorization and use local authorization as the backup.
<Sysname> system-view
[Sysname] domain test
12

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents