1-4
View
Local user view
Parameters
ip ip-address
: Sets the IP address of the user.
mac mac-address
: Sets the MAC address of the user. Here,
mac-address
is in H-H-H format.
idle-cut
second
: Enables the idle-cut function for the local user and sets the allowed idle time. Here,
second
is the allowed idle time, which ranges from 60 to 7,200 seconds.
access-limit max-user-number
: Sets the maximum number of users who can access the switch with
the current username. Here,
max-user-number
ranges from 1 to 1,024.
vlan vlan-id
: Sets the VLAN attribute of the user (that is, specifies to which VLAN the user belongs).
Here,
vlan-id
is an integer ranging from 1 to 4094.
location
: Sets the port binding attribute of the user.
nas-ip ip-address
: Sets the IP address of an access server, so that the user can be bound to a port on
the server. Here,
ip-address
is in dotted decimal notation and is 127.0.0.1 by default (representing this
device). When binding the user to a remote port, you must use
nas-ip
ip-address
to specify a remote
access server IP address. When binding the user to a local port, you need not use
nas-ip
ip-address
.
port port-number
: Sets the port to which you want to bind the user. Here,
port-number
is in the format of
device ID/slot number/port number; the device ID ranges from 1 to 8, the slot number ranges from 0 to
15 (if the bound port has no slot number, just input 0 for this item) and the port number ranges from 1 to
255.
Description
Use the
attribute
command to set the attributes of a user whose service type is lan-access.
Use the
undo attribute
command to cancel attribute settings of the user.
You may use
display local-user
command to view the settings of the attributes.
Examples
# Create local user user1 and set the IP address attribute of user1 to 10.110.50.1, allowing only the user
using the IP address of 10.110.50.1 to use the account user1 for authentication.
<Sysname> system-view
System View: return to User View with Ctrl+Z.
[Sysname] local-user user1
New local user added.
[Sysname-luser- user1] password simple pass1
[Sysname-luser- user1] service-type lan-access
[Sysname-luser-user1] attribute ip 10.110.50.1
authentication
Syntax
authentication
{
radius-scheme
radius-scheme-name
[
local
] |
hwtacacs-scheme
hwtacacs-scheme-name
[
local
] |
local
|
none
}
undo authentication
Содержание H3C S3600 Series
Страница 502: ...2 3 System View return to User View with Ctrl Z Sysname dot1x url http 192 168 19 23 ...
Страница 507: ...3 5 Sysname habp timer 50 ...
Страница 650: ...iii display bootp client 5 3 ip address bootp alloc 5 4 ...
Страница 1085: ...ii schedule reboot delay 3 18 schedule reboot regularity 3 19 system monitor enable 3 20 update fabric 3 21 xmodem get 3 22 ...