72
When you configure RADIUS attribute conversion rules, follow these restrictions and guidelines:
•
The source and destination RADIUS attributes in a rule must use the same data type.
•
The source and destination RADIUS attributes in a rule cannot use the same name.
•
A source RADIUS attribute can be converted only by one criterion, packet type or direction.
•
One source RADIUS attribute cannot be converted to multiple destination attributes.
If you do not specify a source RADIUS attribute, the
undo
attribute
convert
command deletes all
RADIUS attribute conversion rules.
Examples
# In RADIUS DAS view, configure a RADIUS attribute conversion rule to replace the
Ab-Server-String attribute in the received DAE packets with the Cd-User-Roles attribute.
<Sysname> system-view
[Sysname] radius dynamic-author server
[Sysname-radius-da-server] attribute convert Ab-Server-String to Cd-User-Roles received
Related commands
attribute translate
attribute convert (RADIUS scheme view)
Use
attribute convert
to configure a RADIUS attribute conversion rule.
Use
undo attribute convert
to delete RADIUS attribute conversion rules.
Syntax
attribute convert
src-attr-name
to
dest-attr-name
{ {
access-accept
|
access-request
|
accounting
} * | {
received
|
sent
} * }
undo attribute convert
[
src-attr-name
]
Default
No RADIUS attribute conversion rules exist. The system processes RADIUS attributes according to
the principles of the standard RADIUS protocol.
Views
RADIUS scheme view
Predefined user roles
network-admin
mdc-admin
Parameters
src-attr-name
: Specifies the source RADIUS attribute by its name, a case-insensitive string of 1 to 63
characters. The attribute must be supported by the system.
dest-attr-name
: Specifies the destination RADIUS attribute by its name, a case-insensitive string of 1
to 63 characters. The attribute must be supported by the system.
access-accept
: Specifies the RADIUS Access-Accept packets.
access-request
: Specifies the RADIUS Access-Request packets.
accounting
: Specifies the RADIUS accounting packets.
received
: Specifies the received RADIUS packets.
sent
: Specifies the sent RADIUS packets.
Содержание FlexNetwork 7500 Series
Страница 350: ...335 Related commands display port security port security enable ...
Страница 379: ...364 Sysname system view Sysname keychain abc mode absolute Sysname keychain abc tcp kind 252 ...
Страница 519: ...504 Related commands display ssh2 algorithm ssh2 algorithm cipher ssh2 algorithm key exchange ssh2 algorithm mac ...