20
To do…
Use the command…
Remarks
Configure the authorization attributes
for the user group
authorization-attribute
{
acl
acl-
number
|
callback-number
callback-number
|
idle-cut
minute
|
level
level
|
user-profile
profile-name
|
vlan
vlan-id
|
work-directory
directory-name
} *
Optional
By default, no
authorization attribute is
configured for a user
group.
Displaying and maintaining local users and local user groups
To do…
Use the command…
Remarks
Display local user information
display local-user
[
idle-cut
{
disable
|
enable
} |
service-type
{
ftp
|
lan-
access
|
portal
|
ssh
|
telnet
|
terminal
} |
state
{
active
|
block
} |
user-name
user-name
|
vlan
vlan-id
]
[
slot
slot-number
] [
|
{
begin
|
exclude
|
include
}
regular-expression
]
Available in any view
Display the user group configuration
information
display user-group
[
group-name
] [
|
{
begin
|
exclude
|
include
}
regular-
expression
]
Available in any view
Configuring RADIUS schemes
A RADIUS scheme specifies the RADIUS servers that the device can cooperate with and defines a set of
parameters that the device uses to exchange information with the RADIUS servers. There may be
authentication/authorization servers and accounting servers, or primary servers and secondary servers.
The parameters mainly include the IP addresses of the servers, the shared keys, and the RADIUS server
type.
RADIUS scheme configuration task list
Task
Remarks
Required
Specifying the RADIUS authentication/authorization servers
Required
Specifying the RADIUS accounting servers and relevant
parameters
Optional
Setting the shared keys for RADIUS packets
Optional
Setting the maximum number of RADIUS request transmission
attempts
Optional
Setting the supported RADIUS server type
Optional
Setting the status of RADIUS servers
Optional
Setting the username format and traffic statistics units
Optional
Specifying a source IP address for outgoing RADIUS packets
Optional
Setting timers for controlling communication with RADIUS servers
Optional