13
authentication lan-access
Use
authentication lan-access
to specify authentication methods for LAN users.
Use
undo authentication lan-access
to restore the default.
Syntax
In non-FIPS mode:
authentication lan-access
{
ldap-scheme ldap-scheme-name
[
local
] [
none
] |
local
[
none
] |
none
|
radius-scheme
radius-scheme-name
[
local
] [
none
] }
undo authentication lan-access
In FIPS mode:
authentication lan-access
{
ldap-scheme ldap-scheme-name
[
local
] |
local
|
radius-scheme
radius-scheme-name
[
local
] }
undo authentication lan-access
Default
The default authentication methods of the ISP domain are used for LAN users.
Views
ISP domain view
Predefined user roles
network-admin
mdc-admin
Parameters
ldap-scheme
ldap-scheme-name
: Specifies an LDAP scheme by its name, a case-insensitive string
of 1 to 32 characters.
local
: Performs local authentication.
none
: Does not perform authentication.
radius-scheme radius-scheme-name
: Specifies a RADIUS scheme by its name, a case-insensitive
string of 1 to 32 characters.
Usage guidelines
You can specify one primary authentication method and multiple backup authentication methods.
When the primary method is invalid, the device attempts to use the backup methods in sequence.
For example, the
authentication lan-access radius-scheme
radius-scheme-name
local
none
command specifies a primary RADIUS authentication method and two backup methods (local
authentication and no authentication). The device performs RADIUS authentication by default and
performs local authentication when the RADIUS server is invalid. The device does not perform
authentication when both of the previous methods are invalid.
Examples
# In ISP domain
test
, perform local authentication for LAN users.
<Sysname> system-view
[Sysname] domain test
[Sysname-isp-test] authentication lan-access local
# In ISP domain
test
, perform RADIUS authentication for LAN users based on scheme
rd
and use
local authentication as the backup.
<Sysname> system-view
Содержание FlexNetwork 7500 Series
Страница 350: ...335 Related commands display port security port security enable ...
Страница 379: ...364 Sysname system view Sysname keychain abc mode absolute Sysname keychain abc tcp kind 252 ...
Страница 519: ...504 Related commands display ssh2 algorithm ssh2 algorithm cipher ssh2 algorithm key exchange ssh2 algorithm mac ...