1-2
Accounting
AAA supports the following accounting methods:
z
None accounting: No accounting is performed for users.
z
Local accounting: It is not used for charging purposes, but for collecting statistics and limiting the
number of local user connections.
z
Remote accounting: User accounting is performed on a remote RADIUS or TACACS server.
Introduction to ISP Domain
An Internet service provider (ISP) domain is a group of users who belong to the same ISP.
In a multi-ISP environment, the users connected to the same access device may belong to different
domains. Since the users of different ISPs may have different attributes (such as different forms of user
name and password, different service types/access rights), it is necessary to distinguish the users by
setting ISP domains.
You can configure a set of ISP domain attributes (including AAA policy, RADIUS scheme, and so on) for
each ISP domain independently in ISP domain view. Authentication, authorization, and accounting of a
user depends on the AAA methods configured for the domain that the user belongs to. The ISP domain
of a user is determined by the username used for login.
z
If the user enters the username in the form of
userid@domain-name
, the NAS device uses domain
domain-name
to authenticate the user.
z
If the user enters the username in the form of
userid
, the NAS device uses the default domain to
authenticate the user.
The AAA feature allows you to manage users based on their access types:
z
LAN users: Users on a LAN who access through, for example, 802.1X authentication or MAC
authentication.
z
Login users: Users who log in to the device using, for example, SSH, Telnet, and FTP.
This feature allows you to configure different authentication, authorization, and accounting methods for
different users in a domain, or based on their access types if the login username must be in the form of
userid
.
Figure 1-1
Network diagram of per user type AAA configuration
Содержание S3100 Series
Страница 12: ...10 You can e mail your comments about product documentation to info h3c com We appreciate your comments...
Страница 74: ...7 7 Sysname ip http acl 2030...
Страница 270: ...1 51 Sysname GigabitEthernet1 0 1 port trunk permit vlan all...
Страница 287: ...1 14 the interface on which the packet actually arrived The RPF check succeeds and the packet is forwarded...
Страница 579: ...ii Configuration Example 2 4 QoS Profile Configuration Example 2 4...
Страница 713: ...1 22 Total associations 1...
Страница 823: ...1 16...
Страница 1054: ...i Table of Contents Appendix A Acronyms A 1...