18
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Add a local user and enter
network access user view.
local-user user-name
[
class
network
]
By default, no local users exist.
3.
(Optional.) Configure a
password for the local user.
password
{
cipher
|
simple
}
string
By default, no password is configured
for a local user. A local user can pass
authentication after entering the
correct username and passing
attribute checks.
4.
Assign services to the local
user.
service-type
{
ipoe
|
lan-access
|
portal
|
ppp
}
By default, no services are authorized
to a local user.
The
ipoe
and
portal
keywords take
effect only on CSPEX cards.
5.
(Optional.) Set the status of
the local user.
state
{
active
|
block
}
By default, a local user is in active
state and can request network
services.
6.
(Optional.) Set the upper
limit of concurrent logins
using the local user name.
access-limit
max-user-number
By default, the number of concurrent
logins is not limited for the local user.
This command takes effect only when
local accounting is configured for the
local user.
7.
(Optional.) Configure
binding attributes for the
local user.
bind-attribute
{
call-number
call-number
[
:
subcall-number
] |
location
interface
interface-type
interface-number
|
mac
mac-address
|
vlan vlan-id
} *
By default, no binding attributes are
configured for a local user.
8.
(Optional.) Configure
authorization attributes for
the local user.
authorization-attribute
{
acl
acl-number
|
callback-number
callback-number
|
idle-cut
minutes
|
ip
ipv4-address
|
ip-pool
ipv4-pool-name
|
ipv6
ipv6-address
|
ipv6-pool
ipv6-pool-name
|
ipv6-prefix
ipv6-prefix prefix-length
|
{
primary-dns
|
secondary-dns
} {
ip
ipv4-address
|
ipv6
ipv6-address
} |
session-group-profile
session-group-profile-name
|
session-timeout
minutes
|
subscriber-id
subscriber-id
|
url
url-string
|
user-profile
user-profile-name
|
vlan
vlan-id
|
vpn-instance
vpn-instance-name
} *
By default, no authorization attribute
exists for a network access user.
The
user-profile user-profile-name
option takes effect only on CSPEX
cards.
9.
(Optional.) Assign the local
user to a user group.
group
group-name
By default, a local user belongs to the
user group
system
.
Configuring local guest attributes
Create local guests and configure guest attributes to control temporary network access behavior.
Guests can access the network after passing local authentication. You can configure the recipient
addresses and email attribute information to the local guests and guest sponsors.