1-23
<Sysname> system-view
System View: return to User View with Ctrl+Z.
[Sysname] domain aabbcc.net
New Domain added.
[Sysname-isp-aabbcc.net] radius-scheme extended
scheme
Syntax
scheme
{
local
|
none
|
radius-scheme
radius-scheme-name
[
local
] |
hwtacacs-scheme
hwtacacs-scheme-name
[
local
] }
undo scheme
[
none
|
radius-scheme
|
hwtacacs-scheme
]
View
ISP domain view
Parameters
radius-scheme-name
: Name of a RADIUS scheme, a string of up to 32 characters.
hwtacacs-scheme-name
: Name of a HWTACACS scheme, a string of up to 32 characters.
local
: Specifies to use local authentication.
none
: Specifies not to perform authentication.
Description
Use the
scheme
command to configure an AAA scheme for current ISP domain.
Use the
undo scheme
command to restore the default AAA scheme configuration for the ISP domain.
By default, the ISP domain uses the
local
AAA scheme.
Note that:
z
When you execute the
scheme
command to reference a RADIUS scheme in current ISP domain,
the referenced RADIUS scheme must already exist.
z
If you execute the
scheme
radius-scheme radius-scheme-name local
command, the local
scheme is used as the secondary scheme in case no RADIUS server is available. That is, if the
communication between the switch and a RADIUS server is normal, no local authentication is
performed; otherwise, local authentication is performed.
z
If you execute the
scheme
hwtacacs-scheme hwtacacs-scheme-name local
command, the local
scheme is used as the secondary scheme in case no TACACS server is available. That is, if the
communication between the switch and a TACACS server is normal, no local authentication is
performed; If the TACACS server is not reachable or there is a key error or NAS IP error, local
authentication is performed.
z
If you execute the
scheme
local
or
scheme
none
command to use
local
or
none
as the primary
scheme, the local authentication is performed or no authentication is performed. In this case, no
secondary scheme can be specified and therefore no scheme switching will occur.
Содержание 5500-EI PWR
Страница 43: ...2 6...
Страница 76: ...1 17...
Страница 228: ...ii stp transmit limit 1 44 vlan mapping modulo 1 45 vlan vpn tunnel 1 46...
Страница 477: ...5 24 Sysname vlan 2 Sysname vlan2 service type multicast...
Страница 503: ...2 3 System View return to User View with Ctrl Z Sysname dot1x url http 192 168 19 23...
Страница 519: ...iii...
Страница 597: ...2 2 security policy server 192 168 0 1 user name format without domain...
Страница 648: ...1 9 Examples Clear static ARP entries Sysname reset arp static...
Страница 663: ...4 3 Sysname resilient arp interface vlan interface 2...
Страница 767: ...1 28 From 12 00 Jan 1 2008 to 12 00 Jun 1 2008...
Страница 1111: ...ii xmodem get 3 18...
Страница 1314: ...A 44 Z...