Operation Manual - Security
Quidway S3000 Series Ethernet Switches
Chapter 2 AAA and RADIUS Protocol Configuration
2-4
Quidway Series Ethernet Switches ISP domain view, you can configure a complete set
of exclusive ISP domain attributes on a per-ISP domain basis, which includes AAA
policy ( RADIUS server group applied etc.)
For Quidway Series Ethernet Switches, each supplicant belongs to an ISP domain. Up
to 16 domains can be configured in the system. If a user has not reported its ISP
domain name, the system will put it into the default domain.
Perform the following configurations in system view.
Table 2-1
Create/Delete ISP domain
Operation
Command
Create ISP domain or enter the view of a specified
domain.
domain
[
isp-name |
default
{
disable
|
enable
isp-name
}]
Remove a specified ISP domain
undo domain
isp-name
By default, a domain named “system” has been created in the system. The attributes of
“system” are all default valuesthere is no ISP domain in the system.
2.2.2 Configure Relevant Attributes of ISP Domain
The relevant attributes of ISP domain include the adopted RADIUS server group, state,
and maximum number of supplicants . Where,
z
The adopted RADIUS server group is the one used by all the users in the ISP
domain. The RADIUS server group can be used for RADIUS authentication or
accounting. By default, the default RADIUS server group is used. The command
shall be used together with the commands of setting RADIUS server and server
cluster. For details, refer to the following Configuring RADIUS section of this
chapter.
z
Every ISP has active/block states. If an ISP domain is in active state, the users in it
can request for network service, while in block state, its users cannot request for
any network service, which will not affect the users already online. An ISP is in the
block state when it is created. No user in the domain is allowed to request for
network service.
z
Maximum number of supplicants specifies how many supplicants can be
contained in the ISP. For any ISP domain, there is no limit to the number of
supplicants by default.
z
The idle cut function means: If the traffic from a certain connection is lower than
the defined traffic, cut off this connection.
z
Perform the following configurations in ISP domain view.