1-11
none
: Does not perform any authorization. In this case, an authenticated user is automatically
authorized with the corresponding default rights.
radius-scheme radius-scheme-name
: Specifies a RADIUS scheme by its name, which is a string of 1
to 32 characters.
Description
Use the
authorization default
command to configure the authorization method for all types of users.
Use the
undo authorization default
command to restore the default.
By default, the authorization method for all types of users is
local
.
Note that:
z
The RADIUS or HWTACACS scheme specified for the current ISP domain must have been
configured.
z
The authorization method specified with the
authorization default
command is for all types of
users and has a priority lower than that for a specific access mode.
z
RADIUS authorization is special in that it takes effect only when the RADIUS authorization
scheme is the same as the RADIUS authentication scheme. If the RADIUS authorization scheme
is different from the RADIUS authentication scheme, RADIUS authorization will fail. In addition, if
a RADIUS authorization fails, the error message returned to the NAS says that the server is not
responding.
Related commands:
authentication default
,
accounting default
,
hwtacacs scheme
,
radius
scheme
.
Examples
# Configure the default ISP domain
system
to use local authorization for all types of users.
<Sysname> system-view
[Sysname] domain system
[Sysname-isp-system] authorization default local
# Configure the default ISP domain
system
to use RADIUS authorization scheme
rd
for all types of
users and use local authorization as the backup.
<Sysname> system-view
[Sysname] domain system
[Sysname-isp-system] authorization default radius-scheme rd local
authorization lan-access
Syntax
authorization lan-access
{
local
|
none
|
radius-scheme
radius-scheme-name
[
local
] }
undo authorization lan-access
View
ISP domain view
Default Level
2: System level
Summary of Contents for E4510-48G
Page 109: ...2 18 Sysname interface bridge aggregation 1 Sysname Bridge Aggregation1 shutdown ...
Page 309: ...6 4 Sysname interface vlan interface 1 Sysname Vlan interface1 ip address dhcp alloc ...
Page 324: ...8 3 Sysname interface vlan interface 1 Sysname Vlan interface1 ip address bootp alloc ...
Page 530: ...2 5 Sysname mvlan 100 subvlan 10 to 15 ...
Page 739: ...8 15 Sysname system view Sysname port security trap addresslearned ...
Page 819: ...13 11 Sysname system view Sysname public key peer key2 import sshkey key pub ...
Page 914: ...5 17 Sysname reset oam ...
Page 1064: ...5 30 Slot 2 Set next configuration file successfully ...
Page 1325: ...21 13 Examples Redirect to member 2 Sysname irf switch to 2 Sysname Slave 2 ...