1-22
To do…
Use the command…
Remarks
Display information about
specified or all user connections
display
connection
[
access-type
{
dot1x
|
mac-authentication
} |
domain
isp-name
|
interface
interface-type interface-number
|
ip
ip-address
|
mac mac-address
|
ucibindex ucib-index
|
user-name
user-name
|
vlan
vlan-id
]
Available in any view
Display information about
specified or all local users
display local-user
[
idle-cut
{
disable
|
enable
} |
service-type
{
ftp
|
lan-access
|
ssh
|
telnet
|
terminal
} |
state
{
active
|
block
} |
user-name
user-name
|
vlan
vlan-id
]
Available in any view
Display configuration information
about a specified user group or all
user groups
display user-group
[
group-name
]
Available in any view
Configuring RADIUS
The RADIUS protocol is configured on a per scheme basis. After creating a RADIUS scheme, you need
to configure the IP addresses and UDP ports of the RADIUS servers for the scheme. The servers
include authentication/authorization servers and accounting servers, or primary servers and secondary
servers. In other words, the attributes of a RADIUS scheme mainly include IP addresses of primary and
secondary servers, shared key, and RADIUS server type.
Actually, the RADIUS protocol configurations only set the parameters necessary for the information
interaction between a NAS and a RADIUS server. For these settings to take effect, you must reference
the RADIUS scheme containing those settings in ISP domain view. For information about the
commands for referencing a scheme, refer to
Configuring AAA
.
When there are users online, you cannot modify RADIUS parameters other than the retransmission
ones and the timers.
Creating a RADIUS Scheme
Before performing other RADIUS configurations, follow these steps to create a RADIUS scheme and
enter RADIUS scheme view:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Create a RADIUS scheme and
enter RADIUS scheme view
radius scheme
radius-scheme-name
Required
Not defined by default