
28
Figure 9
AAA configuration procedure
For login users, you must configure the authentication mode for logging into the user interface as
scheme
.
For more information, see
Logging In to the Device
in the
Fundamentals Configuration Guide
.
Configuring AAA
By configuring AAA, you can provide network access service for legal users, protect the
networking devices, and avoid unauthorized access. You can also configure ISP domains to
perform AAA on accessing users.
Configuration prerequisites
For remote authentication, authorization, or accounting, you must create the RADIUS or
HWTACACS scheme first. For RADIUS scheme configuration, see
. For
HWTACACS scheme configuration, see
Creating an ISP domain
In a networking scenario with multiple ISPs, an access device might connect users of different ISPs.
Because users of different ISPs might have different user attributes (such as username and
password structure, service type, and rights), you must configure ISP domains to distinguish the
users. In addition, you must configure different attribute sets, including AAA methods for the ISP
domains.
For the NAS, each user belongs to an ISP domain. Up to 16 ISP domains can be configured on a
NAS, including the default ISP domain:
system
. If a user does not provide the ISP domain name,
the system assumes that the user belongs to the default ISP domain.