41
Configuring AAA methods for ISP domains
You configure AAA methods for an ISP domain by referencing configured AAA schemes in ISP domain
view. Each ISP domain has a set of default AAA methods, which are local authentication, local
authorization, and local accounting by default and can be customized. If you do not configure any AAA
methods for an ISP domain, the switch uses the system default AAA methods for authentication,
authorization, and accounting of the users in the domain.
Configuration prerequisites
To use local authentication for users in an ISP domain, configure local user accounts (see "
") on the switch.
To use remote authentication, authorization, and accounting, create the required RADIUS, and
HWTACACS, schemes as described in "
".
Creating an ISP domain
In a networking scenario with multiple ISPs, the switch may connect users of different ISPs, and users of
different ISPs may have different user attributes, such as different username and password structures,
different service types, and different rights. To distinguish the users of different ISPs, configure ISP
domains, and configure different AAA methods and domain attributes for the ISP domains.
The switch can accommodate up to 16 ISP domains, including the system-defined ISP domain
system
.
You can specify one of the ISP domains as the default domain.
On the switch, each user belongs to an ISP domain. If a user provides no ISP domain name at login, the
switch considers the user belongs to the default ISP domain.
To create an ISP domain:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Create an ISP domain and
enter ISP domain view.
domain
isp-name
N/A
3.
Return to system view.
quit
N/A
4.
Specify the default ISP
domain.
domain default enable
isp-name
Optional.
By default, the default ISP domain is the
system-defined ISP domain
system
.
NOTE:
To delete the ISP domain that is functioning as the default ISP domain, you must change it to a non-default
ISP domain by using the
undo domain
default
enable
command.
Configuring ISP domain attributes
In an ISP domain, you can configure the following attributes: