
l
If a local user is in active state, the AR1200-S accepts and processes the authentication request
from the user.
l
If a local user is in blocking state, the AR1200-S rejects the authentication request from the
user.
Step 9
(Optional) Run:
local-user
user-name
access-limit
max-number
The maximum number of connections established by the local user is set.
By default, the number of connections established by a user is not limited.
----End
1.3.3 Configuring authentication and authorization Schemes
To use local authentication and authorization, set the authentication mode in an authentication
scheme to local authentication and the authorization mode in an authorization scheme to local
authorization.
Context
By default, the AR1200-S performs local authentication and authorization for access users.
NOTE
The AR1200-S does not support local accounting.
Procedure
l
Configuring an authentication scheme
1.
Run:
system-view
The system view is displayed.
2.
Run:
aaa
The AAA view is displayed.
3.
Run:
authentication-scheme
authentication-scheme-name
An authentication scheme is created and the authentication scheme view is displayed.
By default, the default authentication scheme is used. The default authentication
scheme can be modified, but it cannot be deleted.
4.
Run:
authentication-mode
local
Local authentication is configured.
5.
(Optional) Run:
authentication-super
{
hwtacacs
|
super
}
*
[
none
]
The authentication mode used to upgrade user levels is configured.
Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
1 AAA Configuration
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
8