19
local
: Performs local authorization.
none
: Does not perform authorization. The following default authorization information applies after
users pass authentication:
•
Login users obtain the level-0 user role. Login users include the Telnet, FTP, SFTP, SCP, and
terminal users. Terminal users can access the device through the console port. For more
information about the level-0 user role, see RBAC configuration in
Fundamentals Configuration
Guide
.
•
The working directory for FTP, SFTP, and SCP login users is the root directory of the NAS.
However, the users do not have permission to access the root directory.
•
Non-login users can access the network.
radius-scheme radius-scheme-name
: Specifies a RADIUS scheme by its name, a
case-insensitive string of 1 to 32 characters.
Usage guidelines
The default authorization method is used for all users that support this method and do not have an
authorization method configured.
The RADIUS authorization configuration takes effect only when the authentication method and
authorization method of the ISP domain use the same RADIUS scheme.
You can specify one primary authorization method and multiple backup authorization methods.
When the default authorization method is invalid, the device attempts to use the backup
authorization methods in sequence. For example, the
authorization default
radius-scheme
radius-scheme-name
local
none
command specifies the default RADIUS
authorization method and two backup methods (local authorization and no authorization). The
device performs RADIUS authorization by default and performs local authorization when the
RADIUS server is invalid. The device does not perform authorization when both of the previous
methods are invalid.
Examples
# In ISP domain
test
, use RADIUS scheme
rd
as the primary default authorization method and use
local authorization as the backup.
<Sysname> system-view
[Sysname] domain test
[Sysname-isp-test] authorization default radius-scheme rd local
Related commands
hwtacacs scheme
local-user
radius scheme
authorization lan-access
Use
authorization lan-access
to specify authorization methods for LAN users.
Use
undo authorization lan-access
to restore the default.
Syntax
In non-FIPS mode:
authorization lan-access
{
local
[
none
]
|
none
|
radius-scheme
radius-scheme-name
[
local
]
[
none
]
}
undo authorization lan-access
Summary of Contents for SOHO IE4300
Page 285: ...i Contents Tcl commands 1 cli 1 tclquit 1 tclsh 2...
Page 288: ...i Contents Python commands 1 exit 1 python 1 python filename 2...
Page 291: ...i Contents Automatic configuration commands 1 autodeploy udisk enable 1...
Page 323: ...25 Sysname Ten GigabitEthernet1 0 51 undo shutdown Related commands irf port...
Page 465: ...ii stp vlan enable 55 vlan mapping modulo 55...
Page 602: ...12 Related commands display mvrp statistics...
Page 609: ...i Contents VLAN mapping commands 1 display vlan mapping 1 vlan mapping 2...
Page 678: ...9 Related commands reset pppoe relay statistics...
Page 846: ...i Contents Basic IP forwarding commands 1 display fib 1 ip forwarding table save 2...
Page 1770: ...i Contents Time range commands 1 display time range 1 time range 1...
Page 2026: ...34 Related commands display mac authentication...
Page 2028: ...ii...
Page 2143: ...i Contents User profile commands 1 display user profile 1 user profile 2...
Page 2308: ...61 ipsec transform set...
Page 2531: ...i Contents SAVI commands 1 ipv6 savi down delay 1 ipv6 savi log enable 1 ipv6 savi strict 2...
Page 2534: ...3 Sysname ipv6 savi strict Related commands ipv6 verify source...
Page 2791: ...14 Sysname track 1 Related commands delay display track...
Page 2939: ...9 sntp authentication keyid sntp reliable authentication keyid...
Page 2967: ...27 Related commands apply poe profile poe enable poe max power interface view poe priority...