21
The RADIUS authorization configuration takes effect only when the authentication method and
authorization method of the ISP domain use the same RADIUS scheme.
You can specify one primary authorization method and multiple backup authorization methods.
When the default authorization method is invalid, the device attempts to use the backup
authorization methods in sequence. For example, the
authorization default
radius-scheme
radius-scheme-name
local
none
command specifies the default RADIUS authorization method and
two backup methods (local authorization and no authorization). The device performs RADIUS
authorization by default and performs local authorization when the RADIUS server is invalid. The
device does not perform authorization when both of the previous methods are invalid.
Examples
# In ISP domain
test
, use RADIUS scheme
rd
as the primary default authorization method and use
local authorization as the backup.
<Sysname> system-view
[Sysname] domain test
[Sysname-isp-test] authorization default radius-scheme rd local
Related commands
hwtacacs scheme
local-user
radius scheme
authorization lan-access
Use
authorization lan-access
to specify authorization methods for LAN users.
Use
undo authorization lan-access
to restore the default.
Syntax
In non-FIPS mode:
authorization lan-access
{
local
[
none
] |
none
|
radius-scheme
radius-scheme-name
[
local
]
[
none
]
}
undo authorization lan-access
In FIPS mode:
authorization lan-access
{
local
|
radius-scheme
radius-scheme-name
[
local
] }
undo authorization lan-access
Default
The default authorization methods of the ISP domain are used for LAN users.
Views
ISP domain view
Predefined user roles
network-admin
mdc-admin
Parameters
local
: Performs local authorization.
none
: Does not perform authorization. An authenticated LAN user directly accesses the network.
Содержание FlexNetwork 7500 Series
Страница 350: ...335 Related commands display port security port security enable ...
Страница 379: ...364 Sysname system view Sysname keychain abc mode absolute Sysname keychain abc tcp kind 252 ...
Страница 519: ...504 Related commands display ssh2 algorithm ssh2 algorithm cipher ssh2 algorithm key exchange ssh2 algorithm mac ...