
Operation Manual – AAA RADIUS HWTACACS
H3C S5500-EI Series Ethernet Switches
Chapter 1 AAA/RADIUS/HWTACACS
Configuration
1-22
To do…
Use the command…
Remarks
Specify the
service types
for the user
service-type
{
lan-access
|
{
ssh
|
telnet
|
terminal
} *
[
level level
] }
Required
No service is authorized
to a user by default
Specify
the
service
types for
the user
Authorize the
user to use the
FTP service
and specify a
directory for
the user to
access
service-type ftp
[
ftp-directory directory
]
Optional
By default, no service is
authorized to a user and
anonymous access to
FTP service is not
allowed. If you authorize
a user to use the FTP
service but do not
specify a directory that
the user can access, the
user can access the root
directory of the device
by default.
Set the directory
accessible to FTP/SFTP
users
work-directory
directory-name
Optional
By default, FTP/SFTP
users can access the
root directory.
Set the priority level of the
user
level level
Optional
0 by default
Set attributes for a LAN
access user
attribute
{
access-limit
max-user-number
|
idle-cut minute
|
ip
ip-address
|
location
{
nas-ip ip-address port
slot-number
subslot-number
port-number
|
port
slot-number
subslot-number
port-number
} |
mac
mac-address
|
vlan
vlan-id
} *
Optional
If the user is bound to a
remote port, the
nas-ip
parameter must be
specified. If the user is
bound to a local port, the
nas-ip
parameter does
not need to be specified.
The default value of
nas-ip
is 127.0.0.1,
meaning the current
host.