1-23
Follow these steps to configure the attributes for a user group:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Create a user group and enter user
group view
user-group group-name
Required
Configure the authorization attributes
for the user group
authorization-attribute
{
acl
acl-number
|
callback-number
callback-number
|
idle-cut
minute
|
level
level
|
user-profile
profile-name
|
vlan
vlan-id
|
work-directory
directory-name
} *
Optional
By default, no
authorization attribute is
configured for a user
group.
Tearing down User Connections Forcibly
Follow these steps to tear down user connections forcibly:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Tear down AAA user
connections forcibly on a
distributed device
cut connection
{
all
|
domain
isp-name
|
ucibindex
ucib-index
|
user-name
user-name
} [
slot slot-number
]
Required
Applicable to only LAN access,
and portal user connections at
present.
Tear down AAA user
connections forcibly on a
distributed IRF device
cut connection
{
all
|
domain
isp-name
|
ucibindex
ucib-index
|
user-name
user-name
} [
chassis
chassis-number
slot
slot-number
]
Required
Applicable to only LAN access,
and portal user connections at
present.
Configuring a NAS ID-VLAN Binding
In some application scenarios, it is required to identify the access locations of users. In this case, you
need to configure NAS ID-VLAN bindings on the access device, so that when a user gets online, the
access device can obtain the NAS ID by the access VLAN of the user and then send the NAS ID to the
RADIUS server through the NAS-identifier attribute. For more information about this, refer to
Portal
Configuration
of the
Security Volume
.
Follow these steps to configure a NAS ID-VLAN binding:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Create a NAS ID profile and
enter NAS ID profile view
aaa nas-id profile
profile-name
Required
Configure a NAS ID-VLAN
binding
nas-id nas-identifier bind vlan
vlan-id
Required
By default, no NAS ID-VLAN
binding exists.
Содержание S7906E - Switch
Страница 82: ...1 4 DeviceA interface tunnel 1 DeviceA Tunnel1 service loopback group 1...
Страница 200: ...1 11 DeviceB display vlan dynamic No dynamic vlans exist...
Страница 494: ...ii Displaying and Maintaining Tunneling Configuration 1 45 Troubleshooting Tunneling Configuration 1 45...
Страница 598: ...ii...
Страница 1757: ...4 9...
Страница 1770: ...6 4...
Страница 2017: ...2 11 Figure 2 3 SFTP client interface...
Страница 2062: ...i Table of Contents 1 URPF Configuration 1 1 URPF Overview 1 1 What is URPF 1 1 How URPF Works 1 1 Configuring URPF 1 2...
Страница 2238: ...1 16 DeviceA cfd linktrace service instance 1 mep 1001 target mep 4002...
Страница 2442: ...2 4 Set the interval for sending Syslog or trap messages to 20 seconds Device mac address information interval 20...