25
If an interface is configured with a mandatory authentication domain (for example, an 802.1X
mandatory authentication domain), the device uses the mandatory authentication domain to perform
authentication, authorization, and accounting for users who access the interface through the
specified access type. To display connections of such users, use the
display connection domain
isp-name
command and specify the mandatory authentication domain.
How the device displays the username of a user on an interface configured with a mandatory
authentication domain depends on the format of the username entered by the user at login:
•
If the username does not contain the at sign (@), the device displays the username in the
format
username
@
mandatory
authentication domain name
.
•
If the username contains the at sign (@), the device displays the entered username. For
example, if a user entered the username
aaa@123
at login and the name of the mandatory
authentication domain is
dom
, the device displays the username
aaa@123
, rather than
aaa@123@dom
.
For 802.1X users whose usernames use a forward slash (/) or backward slash (\) as the domain
name delimiter, you cannot query the connections by username. For example, the
display
connection user-name aaa\bbb
command cannot display the connections of the user
aaa\bbb
.
Examples
# Display information about all AAA user connections.
<Sysname> display connection
Slot: 0
Index=0 , Username=telnet@system
IP=10.0.0.1
IPv6=N/A
Total 1 connection(s) matched on slot 0.
Total 1 connection(s) matched.
# Display information about AAA user connections using the index of 0.
<Sysname> display connection ucibindex 0
Slot: 0
Index=0 , Username=telnet@system
IP=10.0.0.1
IPv6=N/A
Access=Admin ,AuthMethod=PAP
Port Type=Virtual ,Port Name=N/A
ACL Group=Disable
User Profile=N/A
CAR=Disable
Priority=Disable
SessionTimeout=60(s), Terminate-Action=Radius-Request
Start=2009-07-16 10:53:03 ,Current=2009-07-16 10:57:06 ,Online=00h04m03s
Total 1 connection matched.
Slot: 1
Total 0 connection matched.
Slot: 2
Total 0 connection matched.
# On the IRF fabric, display information about AAA user connections using the index of 0.
<Sysname> display connection ucibindex 0
Chassis 1 slot: 0
Index=0 , Username=telnet@system