H3C S5810 Series Operation Manual page 425

Ethernet switches
Hide thumbs Also See for S5810 Series:
Table of Contents

Advertisement

2)
Determine the access mode or service type to be configured. With AAA, you can configure an
authorization scheme specifically for each access mode and service type, limiting the authorization
protocols that can be used for access.
3)
Determine whether to configure an authorization method for all access modes or service types.
Follow these steps to configure AAA authorization methods for an ISP domain:
To do...
Enter system view
Enter ISP domain view
Specify
the
authorization method for all
types of users
Specify
the
authorization
method for command line users
Specify
the
authorization
method for login users
The authorization method specified with the authorization default command is for all types of
users and has a priority lower than that for a specific access mode.
RADIUS authorization is special in that it takes effect only when the RADIUS authorization scheme
is the same as the RADIUS authentication scheme. In addition, if a RADIUS authorization fails, the
error message returned to the NAS says that the server is not responding.
With
the
radius-scheme
hwtacacs-scheme-name [ local | none ], local authorization or no authorization is the backup
method and is used only when the remote server is not available.
If the primary authorization method is local or none, the system performs local authorization or
does not perform any authorization; it will never use the RADIUS, HWTACACS, authorization
scheme.
The authorization information of the RADIUS server is sent to the RADIUS client along with the
authentication response message; therefore, you cannot specify a separate RADIUS authorization
server. If you use RADIUS for authorization and authentication, you must use the same scheme
setting for authorization and authentication; otherwise, the system will prompt you with an error
message.
Use the command...
system-view
domain isp-name
authorization
{
hwtacacs-scheme
default
hwtacacs-scheme-name
[ local ] | local | none |
radius-scheme
radius-scheme-name [ local ] }
authorization
{
hwtacacs-scheme
hwtacacs-scheme-name [ local
| none ] | local | none }
authorization
{
hwtacacs-scheme
hwtacacs-scheme-name
[ local ] | local | none |
radius-scheme
radius-scheme-name [ local ] }
radius-scheme-name
1-16
default
Optional
local by default
command
Optional
The
default
method is used by default.
login
Optional
The
default
method is used by default.
local,
Remarks
authorization
authorization
hwtacacs-scheme

Advertisement

Table of Contents
loading

Table of Contents