Operation Manual – AAA-RADIUS-HWTACACS
H3C S3610&S5510 Series Ethernet Switches
Chapter 1 AAA/RADIUS/HWTACACS
Configuration
1-19
Follow these steps to configure an AAA accounting scheme for an ISP domain:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Create an ISP domain
and enter ISP domain
view
domain
isp-name
Required
Enable the accounting
optional feature
accounting optional
Optional
Disabled by default
Specify the default
accounting scheme for all
types of users
accounting default
{
hwtacacs-scheme
hwtacacs-scheme-name
[
local
]
|
local
|
none
|
radius-scheme
radius-scheme-name
[
local
] }
Optional
Local
by default
Specify the accounting
scheme for LAN access
users
accounting lan-access
{
local
|
none
|
radius-scheme
radius-scheme-name
[
local
] }
Optional
The default
accounting
scheme is used by
default.
Specify the accounting
scheme for login users
accounting login
{
hwtacacs-scheme
hwtacacs-scheme-name
[
local
]
|
local
|
none
|
radius-scheme
radius-scheme-name
[
local
] }
Optional
The default
accounting
scheme is used by
default.
Note:
z
With the
accounting optional
command configured, a user that will be
disconnected otherwise can use the network resources even when there is no
available accounting server or the communication with the current accounting
server fails.
z
The accounting scheme specified with the
accounting default
command is for all
types of users and has a priority lower than that for a specific access mode.
z
With the
radius-scheme radius-scheme-name local
or
hwtacacs-scheme
hwtacacs-scheme-name local
keyword and argument combination configured, the
local scheme is the backup scheme and is used only when the RADIUS server or
HWTACACS server is not available.
z
If the primary accounting scheme is
local
or
none
, the system performs local
accounting or does not perform any accounting, rather than uses the RADIUS or
HWTACACS scheme.
z
With the access mode of login, accounting is not supported for FTP services.