49
Step Command
Remarks
2.
Enter ISP domain view.
domain
isp-name
N/A
3.
Place the ISP domain in
active or blocked state.
state
{
active
|
block
}
By default, an ISP domain is in
active state, and users in the
domain can request network
services.
4.
Configure authorization
attributes for authenticated
users in the ISP domain.
authorization-attribute
{
acl
acl-number
|
car inbound cir
committed-information-rate
[
pir
peak-information-rate
]
outbound
cir
committed-information-rate
[
pir
peak-information-rate
] |
idle-cut minutes
[
flow
] [
traffic
{
both
|
inbound
|
outbound
} ] |
igmp max-access-number
max-access-number
|
ip-pool
pool-name
|
ipv6-pool
ipv6-pool-name
|
mld
max-access-number
max-access-number
|
url
url-string
|
user-group
user-group-name
|
user-profile
profile-name
}
The default settings are as
follows:
•
The idle cut feature is
disabled.
•
An IPv4 user can
concurrently join a maximum
of four IGMP multicast
groups.
•
An IPv6 user can
concurrently join a maximum
of four MLD multicast
groups.
•
No other authorization
attributes exist.
5.
Configure the device to
include the idle cut period or
portal user online detection
period in the user online
duration to be sent to the
server.
session-time include-idle-time
By default, the user online
duration sent to the server does
not include the idle cut period or
portal user online detection
period.
Configuring authentication methods for an ISP domain
Configuration prerequisites
Before configuring authentication methods, complete the following tasks:
1.
Determine the access type or service type to be configured. With AAA, you can configure an
authentication method for each access type and service type.
2.
Determine whether to configure the default authentication method for all access types or
service types. The default authentication method applies to all access users. However, the
method has a lower priority than the authentication method that is specified for an access type
or service type.
Configuration guidelines
When configuring authentication methods, follow these guidelines:
•
If the authentication method uses a RADIUS scheme and the authorization method does not
use a RADIUS scheme, AAA accepts only the authentication result from the RADIUS server.
The Access-Accept message from the RADIUS server also includes the authorization
information, but the device ignores the information.
•
If an HWTACACS scheme is specified, the device uses the entered username for role
authentication. If a RADIUS scheme is specified, the device uses the username
$enabn$
on
the RADIUS server for role authentication. The variable
n
represents a user role level. For more
information about user role authentication, see
Fundamentals Configuration Guide
.
Configuration procedure
To configure authentication methods for an ISP domain:
Summary of Contents for FlexFabric 5940 SERIES
Page 251: ...238 ...