Operation Manual – AAA
H3C S3100 Series Ethernet Switches
Chapter 2 AAA Configuration
2-7
Note:
z
If a combined AAA scheme is configured as well as the separate authentication,
authorization and accounting schemes, the separate ones will be adopted in
precedence.
z
RADIUS scheme and local scheme do not support the separation of authentication
and authorization. Therefore, pay attention when you make authentication and
authorization configuration for a domain: When the
scheme radius-scheme
or
scheme local
command is executed and the
authentication
command is not
executed, the authorization information returned from the RADIUS or local scheme
still takes effect even if the
authorization none
command is executed.
z
The switches adopt hierarchical protection for command lines so as to inhibit users
at lower levels from using higher level commands to configure the switches. For
details about configuring a HWTACACS authentication scheme for low-to-high user
level switching, refer to section
Switching
User Level
in the
Command Line Interface
Operation
.
2.1.4 Configuring Dynamic VLAN Assignment
The dynamic VLAN assignment feature enables a switch to dynamically add the switch
ports of successfully authenticated users to different VLANs according to the attributes
assigned by the RADIUS server, so as to control the network resources that different
users can access.
Currently, the switch supports the following two types of assigned VLAN IDs: integer
and string.
z
Integer: If the RADIUS authentication server assigns integer type of VLAN IDs,
you can set the VLAN assignment mode to integer on the switch (this is also the
default mode on the switch). Then, upon receiving an integer ID assigned by the
RADIUS authentication server, the switch adds the port to the VLAN whose VLAN
ID is equal to the assigned integer ID. If no such a VLAN exists, the switch first
creates a VLAN with the assigned ID, and then adds the port to the newly created
VLAN.
z
String: If the RADIUS authentication server assigns string type of VLAN IDs, you
can set the VLAN assignment mode to string on the switch. Then, upon receiving a
string ID assigned by the RADIUS authentication server, the switch compares the
ID with existing VLAN names on the switch. If it finds a match, it adds the port to
the corresponding VLAN. Otherwise, the VLAN assignment fails and the user fails
the authentication.
In actual applications, to use this feature together with Guest VLAN, you should better
set port control to port-based mode. For more information, refer to the section “Basic
802.1x Configuration” of
802.1x Operation Manual.