68
Step Command Remarks
3.
Set the NAS-ID in the ISP
domain.
nas-id
nas-identifier
By default, no NAS-ID is set in an
ISP domain.
Configuring the device ID
RADIUS uses the value of the Acct-Session-ID attribute as the accounting ID for a user. The device
generates an Acct-Session-ID value for each online user based on the system time, random digits,
and device ID.
To configure the device ID:
Step Command Remarks
1.
Enter system view.
system-view
N/A
2.
Configure the device ID.
aaa device-id
device-id
By default, the device ID is 0.
AAA configuration examples
Example: Configuring authentication and authorization for
SSH users by a RADIUS server
Network configuration
As shown in
, configure the router to meet the following requirements:
•
Use the RADIUS server for SSH user authentication and authorization.
•
Include domain names in the usernames sent to the RADIUS server.
•
Assign the default user role
network-operator
to SSH users after they pass authentication.
The RADIUS server runs on IMC. Add an account with username
hello@bbb
on the RADIUS
server.
The RADIUS server and the router use
expert
as the shared key for secure RADIUS communication.
The ports for authentication and accounting are
1812
and
1813
, respectively.
Figure 12 Network diagram
Procedure
1.
Configure the RADIUS server on IMC 5.0: