AAA and RADIUS Protocol Configuration
209
However, the user-privilege level is a global value for all service types. Entering
the following two commands will result in the user having a level of 3 for all
service types. In this case both telnet and SSH:
[4500-SI-luser-adminpwd]
service-type telnet level 1
[4500-SI-luser-adminpwd]
service-type ssh level 3
You can use either
level
or
service-type
command to specify the level for a
local user. If both of these two commands are used, the latest configuration will
take effect.
Disconnecting a User by
Force
Sometimes it is necessary to disconnect a user or a category of users by force. The
system provides the following command to serve this purpose.
Perform the following configurations in System View.
Table 219
Disconnecting a User by Force
By default, no online user will be disconnected by force.
Configuring the RADIUS
Protocol
For the Switch 4500, the RADIUS protocol is configured on the per RADIUS
scheme basis. In a real networking environment, a RADIUS scheme can be an
independent RADIUS server or a set of primary/secondary RADIUS servers with the
same configuration but two different IP addresses. Accordingly, attributes of every
RADIUS scheme include IP addresses of primary and secondary servers, shared key
and RADIUS server type, etc.
RADIUS protocol configuration only defines some necessary parameters used for
information interaction between NAS and RADIUS Server. To make these
parameters effective, it is necessary to configure, in the view, an ISP domain to use
the RADIUS scheme and specify it to use RADIUS AAA schemes. For more
information about the configuration commands, refer to the AAA Configuration
section above.
RADIUS protocol configuration includes:
■
Creating/Deleting a RADIUS Scheme
■
Configuring RADIUS Authentication/ Authorization Servers
■
Configuring RADIUS Accounting Servers and the Related Attributes
■
Setting the RADIUS Packet Encryption Key
■
Setting Retransmission Times of RADIUS Request Packet
■
Setting the Supported Type of the RADIUS Server
■
Setting the RADIUS Server State
■
Setting the Username Format Transmitted to the RADIUS Server
Operation
Command
Disconnect a user by
force
cut connection { all | access-type { dot1x | gcm |
mac-authentication } | domain
domain_name
|
interface
interface_type interface_number
| ip
ip_address
| mac
mac_address
| radius-scheme
radius_scheme_name
| vlan
vlanid
| ucibindex
ucib_index
| user-name
user_name
}
Содержание Switch 4500 26-Port
Страница 16: ...14 ABOUT THIS GUIDE...
Страница 58: ...56 CHAPTER 2 PORT OPERATION...
Страница 104: ...102 CHAPTER 5 NETWORK PROTOCOL OPERATION...
Страница 130: ...128 CHAPTER 6 IP ROUTING PROTOCOL OPERATION...
Страница 154: ...152 CHAPTER 7 ACL CONFIGURATION...
Страница 228: ...226 CHAPTER 11 802 1X CONFIGURATION...
Страница 250: ...248 CHAPTER 14 DEVICE MANAGEMENT...
Страница 280: ...278 CHAPTER 15 SYSTEM MAINTENANCE AND DEBUGGING...
Страница 312: ...310 CHAPTER 18 NTP CONFIGURATION...
Страница 340: ...338 CHAPTER 19 SSH TERMINAL SERVICES...
Страница 350: ...348 CHAPTER 20 PASSWORD CONTROL CONFIGURATION OPERATIONS...
Страница 388: ...386 APPENDIX B RADIUS SERVER AND RADIUS CLIENT SETUP...