42
To do…
Use the command…
Remarks
5.
Specify the command
accounting method.
accounting command hwtacacs-
scheme
hwtacacs-scheme-name
Optional.
The default accounting method
is used by default.
6.
Specify the accounting
method for LAN users.
accounting lan-access
{
local
|
none
|
radius-scheme
radius-scheme-name
[
local
|
none
] }
Optional.
The default accounting method
is used by default.
7.
Specify the accounting
method for login users.
accounting login
{
hwtacacs-scheme
hwtacacs-scheme-name
[
local
] |
local
|
none
|
radius-scheme
radius-
scheme-name
[
local
] }
Optional.
The default accounting method
is used by default.
If you configure the
accounting optional
command, the limit on the number of local user connections is
not effective.
The accounting method specified with the
accounting default
command is for all types of users and has a
priority lower than that for a specific access type.
If you specify the
radius-scheme
radius-scheme-name
local
,
hwtacacs-scheme
hwtacacs-scheme-name
local
option when you configure an accounting method, local accounting is the backup method and is
used only when the remote server is not available.
If you specify only the
local
or
none
keyword in an accounting method configuration command, the
switch has no backup accounting method and performs only local accounting or does not perform any
accounting.
Accounting is not supported for FTP services.
Tearing down user connections
To do…
Use the command…
Remarks
1.
Enter system view.
system-view
—
2.
Tear down AAA user
connections.
cut connection
{
access-type
{
dot1x
|
mac-
authentication
} |
all
|
domain
isp-name
|
interface
interface-type interface-number
|
ip
ip-
address
|
mac
mac-address
|
ucibindex
ucib-
index
|
user-name
user-name
|
vlan
vlan-id
} [
slot
slot-number
]
Required
Applies only to LAN
user connections
Configuring a NAS ID-VLAN binding
The access locations of users can be identified by their access VLANs. In application scenarios where
identifying the access locations of users is required, configure NAS ID-VLAN bindings on the switch.
Then, when a user gets online, the switch obtains the NAS ID by the access VLAN of the user and sends
the NAS ID to the RADIUS server through the NAS-identifier attribute.
To configure a NAS ID-VLAN binding:
To do…
Use the command…
Remarks
1.
Enter system view.
system-view
—
Содержание A5830 Series
Страница 207: ...199 Figure 62 SFTP client interface ...