
Step 3
Run:
domain
domain-name
A domain is created and the domain view is displayed.
The AR1200-S has two default domains:
default
and
default_admin
. The
default
domain is
used by common access users and the
default_admin
domain is used by administrators.
Step 4
Run:
authentication-scheme
authentication-scheme-name
An authentication scheme is applied to the domain.
By default, the default authentication scheme is applied to a domain.
Step 5
Run:
authorization-scheme
authorization-scheme-name
An authorization scheme is applied to the domain.
By default, no authorization scheme is applied to a domain.
Step 6
(Optional) Run:
state
{
active
|
block
}
The domain status is configured.
When a domain is in blocking state, users in this domain cannot log in. By default, a domain is
in active state after being created.
Step 7
Run:
quit
Return to the domain view.
Step 8
(Optional) Run:
domain-name-delimiter
delimiter
The domain name delimiter is configured.
The domain name delimiter can be any of the following: \ / : < > | @ ' %.
By default, the domain name delimiter is @.
----End
1.3.5 Checking the Configuration
Prerequisites
The configurations of local authentication and authorization are complete.
Procedure
l
Run the
display aaa configuration
command to check the AAA summary.
l
Run the
display authentication-scheme
[
authentication-scheme-name
] command to
check the authentication scheme configuration.
Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
1 AAA Configuration
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
10