![H3C S9500E Series Security Configuration Manual Download Page 31](http://html1.mh-extra.com/html/h3c/s9500e-series/s9500e-series_security-configuration-manual_3156952031.webp)
31
To do…
Use the command…
Remarks
5.
Specify the authentication
method for login users
authentication login
{
hwtacacs-scheme
hwtacacs-
scheme-name
[
local
] |
local
|
none
|
radius-scheme
radius-
scheme-name
[
local
] }
Optional
•
The default authentication
method is used by default.
6.
Specify the authentication
method for portal users
authentication portal
{
local
|
none
|
radius-scheme
radius-
scheme-name
[
local
] }
Optional
The default authentication method
is used by default.
•
The authentication method specified with the
authentication default
command is for all types of users
and has a priority lower than that for a specific access mode.
•
With an authentication method that references a RADIUS scheme, AAA accepts only the authentication
result from the RADIUS server. The Access-Accept message from the RADIUS server includes the
authorization information, but the authentication process ignores the information.
•
With the
radius-scheme
radius-scheme-name
local
, or
hwtacacs-scheme
hwtacacs-scheme-name
local
keyword and configured argument combination, local authentication is the backup and used only
when the remote server is not available.
•
If the primary authentication method is
local
or
none
, the system performs local authentication or does
not perform any authentication, and does not use any RADIUS or HWTACACS authentication scheme.
Configuring AAA authorization methods for an ISP domain
In AAA, authorization is a separate process at the same level as authentication and accounting. Its
responsibility is to send authorization requests to the specified authorization server and to send
authorization information to users. Authorization method configuration is optional in AAA
configuration.
AAA supports the following authorization methods:
•
No authorization (none): All users are trusted and authorized. A user gets the corresponding
default rights of the system.
•
Local authorization (local): Users are authorized by the access device according to the
attributes configured for them.
•
Remote authorization (scheme): The access device cooperates with a RADIUS or HWTACACS
server to authorize users. RADIUS authorization is bound with RADIUS authentication.
RADIUS authorization can work only after RADIUS authentication is successful, and the
authorization information is carried in the Access-Accept message. HWTACACS authorization
is separate from HWTACACS authentication, and the authorization information is carried in
the authorization response after successful authentication. You can configure local
authorization or no authorization as the backup in case the remote server is not available.
By default, an ISP domain uses the local authorization method. If the no authorization method
(
none
) is configured, the users are not required to be authorized, in which case an authenticated
user has the default setting. The default setting is visiting (the lowest one) for EXEC users. EXEC