
34
To do…
Use the command…
Remarks
5.
Specify the accounting method
for LAN users
accounting lan-access
{
local
|
none
|
radius-scheme
radius-
scheme-name
[
local
] }
Optional
The default accounting method is
used by default.
6.
Specify the accounting method
for login users
accounting login
{
hwtacacs-
scheme
hwtacacs-scheme-name
[
local
] |
local
|
none
|
radius-
scheme
radius-scheme-name
[
local
] }
Optional
The default accounting method is
used by default.
7.
Specify the accounting method
for portal users
accounting portal
{
local
|
none
|
radius-scheme
radius-
scheme-name
[
local
] }
Optional
The default accounting method is
used by default.
•
With the
accounting optional
command, a user that is disconnected can continue to use network
resources even if the current accounting server.
•
Local accounting works with the
access-limit
command in the local user view to limit the number of
local user connections. However, if using the
accounting optional
command, you cannot limit on the
number of local user connections.
•
The
accounting default
command specifies an accounting method for all types of users and has a
priority lower than that for a specific access mode.
•
With the
radius-scheme
radius-scheme-name
local
or
hwtacacs-scheme
hwtacacs-scheme-name
local
keyword and argument combination configured, local accounting is used only when the remote
server is not available.
•
If the primary accounting method is
local
or
none
, the system performs local accounting or does not
perform any accounting, and does not use the RADIUS or HWTACACS accounting scheme.
•
In login access mode, accounting is not supported for FTP services.
Configuring local user attributes
For local authentication, you must create local users and configure user attributes on the switch as
needed.
A local user represents a set of user attributes configured on a local switch that is uniquely
identified by the username. For a user requesting network service to pass local authentication, you
must add an entry in the local user database of the switch.
Each local user belongs to a local user group and bears all attributes of the group, such as the
authorization attributes. For more information about local user group, see
.
When configuring local users and groups, consider the effective ranges and priority relationship of
all user group attributes. You can configure an authorization attribute in user group view or local
user view, to make the attribute effective on all local users of the group or only the local user. An
authorization attribute configured in local user view takes precedence over the same attribute
configured in user group view.