22
radius-scheme radius-scheme-name
: Specifies a RADIUS scheme by its name, a case-insensitive
string of 1 to 32 characters.
Usage guidelines
The RADIUS authorization configuration takes effect only when authentication and authorization
methods of the ISP domain use the same RADIUS scheme.
You can specify one primary authorization method and multiple backup authorization methods.
When the primary method is invalid, the device attempts to use the backup methods in sequence.
For example, the
authorization lan-access radius-scheme
radius-scheme-name
local
none
command specifies a primary RADIUS authorization method and two backup methods (local
authorization and no authorization). The device performs RADIUS authorization by default and
performs local authorization when the RADIUS server is invalid. The device does not perform
authorization when both of the previous methods are invalid.
Examples
# In ISP domain
test
, perform local authorization for LAN users.
<Sysname> system-view
[Sysname] domain test
[Sysname-isp-test] authorization lan-access local
# In ISP domain
test
, perform RADIUS authorization for LAN users based on scheme
rd
and use
local authorization as the backup.
<Sysname> system-view
[Sysname] domain test
[Sysname-isp-test] authorization lan-access radius-scheme rd local
Related commands
authorization default
local-user
radius scheme
authorization login
Use
authorization login
to specify authorization methods for login users.
Use
undo authorization login
to restore the default.
Syntax
In non-FIPS mode:
authorization
login
{
hwtacacs-scheme
hwtacacs-scheme-name
[
radius-scheme
radius-scheme-name
] [
local
] [
none
]
|
local
[
none
] |
none
|
radius-scheme
radius-scheme-name
[
hwtacacs-scheme
hwtacacs-scheme-name
] [
local
] [
none
]
}
undo authorization login
In FIPS mode:
authorization
login
{
hwtacacs-scheme
hwtacacs-scheme-name
[
radius-scheme
radius-scheme-name
] [
local
] |
local
|
radius-scheme
radius-scheme-name
[
hwtacacs-scheme
hwtacacs-scheme-name
] [
local
] }
undo authorization login
Default
The default authorization methods of the ISP domain are used for login users.
Содержание FlexNetwork 7500 Series
Страница 350: ...335 Related commands display port security port security enable ...
Страница 379: ...364 Sysname system view Sysname keychain abc mode absolute Sysname keychain abc tcp kind 252 ...
Страница 519: ...504 Related commands display ssh2 algorithm ssh2 algorithm cipher ssh2 algorithm key exchange ssh2 algorithm mac ...