25
Examples
# In ISP domain
test
, perform user role authentication based on HWTACACS scheme
tac
.
<Sysname> system-view
[Sysname] super authentication-mode scheme
[Sysname] domain test
[Sysname-isp-test] authentication super hwtacacs-scheme tac
Related commands
authentication default
hwtacacs scheme
radius scheme
authorization advpn
Use
authorization advpn
to configure the authorization method for ADVPN users.
Use
undo authorization advpn
to restore the default.
Syntax
In non-FIPS mode:
authorization advpn
{
local
[
none
] |
none
|
radius-scheme
radius-scheme-name
[
local
]
[
none
] }
undo authorization advpn
In FIPS mode:
authorization advpn
{
local
|
radius-scheme
radius-scheme-name
[
local
] }
undo authorization advpn
Default
The default authorization method of the ISP domain is used for ADVPN users.
Views
ISP domain view
Predefined user roles
network-admin
Parameters
local
: Performs local authorization.
none
: Does not perform authorization.
radius-scheme radius-scheme-name
: Specifies a RADIUS scheme by its name, a case-insensitive
string of 1 to 32 characters.
Usage guidelines
The RADIUS authorization configuration takes effect only when authentication and authorization
methods of the ISP domain use the same RADIUS scheme.
You can specify one primary authorization method and multiple backup authorization methods.
When the primary method is invalid, the device attempts to use the backup methods in sequence.
For example, the
authorization advpn radius-scheme
radius-scheme-name
local
none
command
specifies a primary RADIUS authorization method and two backup methods (local authorization and
no authorization). The device performs RADIUS authorization by default and performs local
Summary of Contents for FlexNetwork MSR Series
Page 1005: ...987 ...