46
Specifying the LDAP authentication server
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter LDAP scheme view.
ldap scheme
ldap-scheme-name
N/A
3.
Specify the LDAP
authentication server.
authentication-server
server-name
By default, no LDAP authentication
server is specified.
Specifying the LDAP authorization server
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter LDAP scheme view.
ldap scheme
ldap-scheme-name
N/A
3.
Specify the LDAP
authorization server.
authorization-server
server-name
By default, no LDAP authorization
server is specified.
Specifying an LDAP attribute map for LDAP authorization
Specify an LDAP attribute map for LDAP authorization to convert LDAP attributes obtained from the
LDAP authorization server to device-recognizable AAA attributes.
You can specify only one LDAP attribute map in an LDAP scheme.
To specify an LDAP attribute map for LDAP authorization:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter LDAP scheme view.
ldap scheme
ldap-scheme-name
N/A
3.
Specify an LDAP attribute
map.
attribute-map
map-name
By default, no LDAP attribute map is
specified.
Displaying and maintaining LDAP
Execute
display
commands in any view.
Task Command
Display the configuration of LDAP schemes.
display ldap scheme
[
ldap-scheme-name
]
Configuring AAA methods for ISP domains
You configure AAA methods for an ISP domain by specifying configured AAA schemes in ISP
domain view. Each ISP domain has a set of system-defined AAA methods, which are local
authentication, local authorization, and local accounting. If you do not configure any AAA methods
for an ISP domain, the device uses the system-defined AAA methods for users in the domain.
AAA is available to login users after you enable
scheme
authentication for the users. For more
information about the login authentication modes, see
Fundamentals Configuration Guide
.
Содержание FlexFabric 5940 SERIES
Страница 251: ...238 ...