1-22
To do…
Use the command…
Remarks
Tear down AAA user
connections forcibly
cut connection
{
access-type
{
dot1x
|
mac-authentication
|
portal
} |
all
|
domain isp-name
|
interface interface-type
interface-number
|
ip
ip-address
|
mac mac-address
|
ucibindex ucib-index
|
user-name user-name
|
vlan
vlan-id
}
Required
Applies to only LAN access and
portal user connections at
present
Displaying and Maintaining AAA
To do…
Use the command…
Remarks
Display the configuration
information of a specified ISP
domain or all ISP domains
display domain
[
isp-name
]
Available in any view
Display information about
specified or all user connections
display
connection
[
access-type
{
dot1x
|
mac-authentication
|
portal
} |
domain
isp-name
|
interface
interface-type interface-number
|
ip
ip-address
|
mac mac-address
|
ucibindex ucib-index
|
user-name
user-name
|
vlan
vlan-id
]
Available in any view
Display information about
specified or all local users
display local-user
[
idle-cut
{
disable
|
enable
} |
service-type
{
ftp
|
lan-access
|
portal
|
ssh
|
telnet
|
terminal
} |
state
{
active
|
block
} |
user-name
user-name
|
vlan
vlan-id
]
Available in any view
Display configuration
information about a specified
user group or all user groups
display user-group
[
group-name
]
Available in any view
Configuring RADIUS
The RADIUS protocol is configured on a per scheme basis. After creating a RADIUS scheme, you need
to configure the IP addresses and UDP ports of the RADIUS servers for the scheme. The servers
include authentication/authorization servers and accounting servers, or primary servers and secondary
servers. In other words, the attributes of a RADIUS scheme mainly include IP addresses of primary and
secondary servers, shared key, and RADIUS server type.
Actually, the RADIUS protocol configurations only set the parameters necessary for the information
interaction between a NAS and a RADIUS server. For these settings to take effect, you must reference
the RADIUS scheme containing those settings in ISP domain view. For information about the
commands for referencing a scheme, refer to
.
Summary of Contents for S5500-SI Series
Page 161: ...3 10 GigabitEthernet1 0 1 2 MANUAL...
Page 220: ...1 7 Clearing ARP entries from the ARP table may cause communication failures...
Page 331: ...1 7 1 1 ms 1 ms 1 ms 1 1 6 1 2 1 ms 1 ms 1 ms 1 1 4 1 3 1 ms 1 ms 1 ms 1 1 2 2 Trace complete...
Page 493: ...2 8...
Page 1111: ...1 10 Installing patches Installation completed and patches will continue to run after reboot...