176
C
HAPTER
23: AAA&RADIUS C
ONFIGURATION
■
If you execute the
scheme
local
command, the local scheme is adopted as the
primary scheme. In this case, only local authentication is performed, no RADIUS
authentication is performed.
■
If you execute the
scheme
none
command, no authentication is performed.
Configuring separate AAA schemes
You can use the
authentication
,
authorization
, and
accounting
commands to
specify a scheme for each of the three AAA functions (authentication, authorization
and accounting) respectively. The following gives the implementations of this separate
way for the services supported by AAA.
■
For terminal users
Authentication: RADIUS, local, RADIUS-local or none.
Authorization: none.
Accounting: RADIUS or none.
You can configure combined authentication, authorization and accounting schemes
by using the above implementations.
■
For FTP users
■
Only authentication is supported for FTP users.
■
Authentication: RADIUS, local, or RADIUS-local.
Perform the following configuration in ISP domain view.
■
If a bound AAA scheme is configured as well as the separate authentication,
authorization and accounting schemes, the separate ones will be adopted in
precedence.
■
RADIUS scheme and local scheme do not support the separation of authentication
and authorization. Therefore, pay attention when you make authentication and
authorization configuration for a domain: if the
scheme radius-scheme
or
scheme local
command is executed, the
authorization none
command is
executed, while the
authentication
command is not executed, the authorization
information returned from the RADIUS or local scheme still takes effect.
Table 138
Configure separate AAA schemes
Operation
Command
Description
Enter system view
system-view
—
Create an ISP domain or enter
the view of an existing ISP
domain
domain
isp-name
Required
Configure an authentication
scheme for the ISP domain
authentication
{
radius-scheme
radius-scheme-name
[
local ]
|
local
|
none }
Optional
By default, no separate
authentication scheme
is configured.
Allow users in current ISP
domain to access the network
services without being
authorized
authorization none
Optional
By default, no separate
authorization scheme is
configured.
Configure an accounting
scheme for the ISP domain
accounting
{
none
|
radius-scheme
radius-scheme-name
}
Optional
By default, no separate
accounting scheme is
configured.
Summary of Contents for 3CR17660-91
Page 10: ...8 CONTENTS ...
Page 14: ...4 ABOUT THIS GUIDE ...
Page 46: ...32 CHAPTER 5 LOGGING IN THROUGH WEB BASED NETWORK MANAGEMENT SYSTEM ...
Page 48: ...34 CHAPTER 6 LOGGING IN THROUGH NMS ...
Page 60: ...46 CHAPTER 9 VLAN CONFIGURATION ...
Page 64: ...50 CHAPTER 10 MANAGEMENT VLAN CONFIGURATION ...
Page 80: ...66 CHAPTER 13 GVRP CONFIGURATION ...
Page 98: ...84 CHAPTER 15 LINK AGGREGATION CONFIGURATION ...
Page 112: ...98 CHAPTER 18 MAC ADDRESS TABLE MANAGEMENT ...
Page 126: ...112 CHAPTER 19 LOGGING IN THROUGH TELNET ...
Page 162: ...148 CHAPTER 20 MSTP CONFIGURATION ...
Page 274: ...260 CHAPTER 29 IGMP SNOOPING CONFIGURATION ...
Page 276: ...262 CHAPTER 30 ROUTING PORT JOIN TO MULTICAST GROUP CONFIGURATION ...
Page 298: ...284 CHAPTER 33 SNMP CONFIGURATION ...
Page 304: ...290 CHAPTER 34 RMON CONFIGURATION ...
Page 338: ...324 CHAPTER 36 SSH TERMINAL SERVICES ...
Page 356: ...342 CHAPTER 38 FTP AND TFTP CONFIGURATION ...
Page 365: ...Information Center Configuration Example 351 S4200G terminal logging ...
Page 366: ...352 CHAPTER 39 INFORMATION CENTER ...
Page 378: ...364 CHAPTER 40 BOOTROM AND HOST SOFTWARE LOADING ...
Page 384: ...370 CHAPTER 41 Basic System Configuration and Debugging ...
Page 388: ...374 CHAPTER 43 NETWORK CONNECTIVITY TEST ...
Page 406: ...392 CHAPTER 45 CONFIGURATION OF NEWLY ADDED CLUSTER FUNCTIONS ...