47
Step Command
Remarks
3.
Enable the accounting
optional feature.
accounting optional
Optional.
Disabled by default.
With the accounting optional
feature, a switch allows users to
use network resources when no
accounting server is available
or communication with all
accounting servers fails.
4.
Specify the default accounting
method for all types of users.
accounting default
{
hwtacacs-scheme
hwtacacs-scheme-name
[
local
] |
local
|
none
|
radius-scheme
radius-scheme-name
[
local
] }
Optional.
The default accounting method
is
local
for all types of users.
5.
Specify the command
accounting method.
accounting command
hwtacacs-scheme
hwtacacs-scheme-name
Optional.
The default accounting method
is used by default.
6.
Specify the accounting
method for LAN users.
accounting lan-access
{
local
|
none
|
radius-scheme
radius-scheme-name
[
local
|
none
] }
Optional.
The default accounting method
is used by default.
7.
Specify the accounting
method for login users.
accounting login
{
hwtacacs-scheme
hwtacacs-scheme-name
[
local
] |
local
|
none
|
radius-scheme
radius-scheme-name
[
local
] }
Optional.
The default accounting method
is used by default.
8.
Specify the accounting
method for portal users.
accounting portal
{
local
|
none
|
radius-scheme
radius-scheme-name
[
local
] }
Optional.
The default accounting method
is used by default.
Tearing down user connections
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Tear down AAA user
connections.
cut connection
{
access-type
{
dot1x
|
mac-authentication
|
portal
} |
all
|
domain
isp-name
|
interface
interface-type
interface-number
|
ip
ip-address
|
mac
mac-address
|
ucibindex
ucib-index
|
user-name
user-name
|
vlan
vlan-id
} [
slot
slot-number
]
The command applies
only to LAN and
portal user
connections.
Configuring a NAS ID-VLAN binding
The access locations of users can be identified by their access VLANs. In application scenarios where
identifying the access locations of users is a must, configure NAS ID-VLAN bindings on the switch. Then,
when a user gets online, the switch obtains the NAS ID by the access VLAN of the user and sends the
NAS ID to the RADIUS server through the NAS-identifier attribute.
To configure a NAS ID-VLAN binding: