Operation Manual – AAA&RADIUS
Quidway S3100 Series Ethernet Switches
Chapter 1 AAA&RADIUS Configuration
Huawei Technologies Proprietary
1-14
Note:
z
If a bound AAA scheme is configured as well as the separate authentication,
authorization and accounting schemes, the separate ones will be adopted in
precedence.
z
RADIUS scheme and local scheme do not support the separation of authentication
and authorization. Therefore, pay attention when you make authentication and
authorization configuration for a domain: if the
scheme radius-scheme
or
scheme
local
command is executed, the
authorization none
command is executed, while
the
authentication
command is not executed, the authorization information
returned from the RADIUS or local scheme still takes effect.
1.4 Dynamic VLAN Assignment Configuration
The dynamic VLAN assignment feature enables a switch to dynamically add the ports
of the successfully authenticated users to different VLANs according to the attributes
assigned by the RADIUS server, so as to control the network resources that different
users can access.
Currently, the switch supports the following two types of VLAN IDs assigned by its
RADIUS authentication server.
z
Integer: The switch adds a port to the corresponding VLAN according to the VLAN
ID (integer value) assigned by the RADIUS authentication server. If the VLAN
does not exist, it first creates the VLAN, and then adds the port to the newly
created VLAN.
z
String: The switch compares the VLAN ID (string value) assigned by the RADIUS
authentication server with the existing VLAN names on the switch. If it finds a
match, it adds the port to the corresponding VLAN. Otherwise, the VLAN
assignment fails and the user cannot pass the authentication.
In actual applications, to use this feature together with Guest VLAN, you should better
set port control to port-based mode; if you set port control to MAC-address-based
mode, each port can be connected to only one user.
1.4.1 Configuring Dynamic VLAN Assignment
Table 1-8
Configure dynamic VLAN assignment
Operation
Command
Description
Enter system view
system-view
—
Create an ISP
domain and enter its
view
domain
isp-name
—
Содержание Quidway S3100 Series
Страница 21: ...HUAWEI Quidway S3100 Series Ethernet Switches Operation Manual CLI Huawei Technologies Proprietary ...
Страница 33: ...HUAWEI Quidway S3100 Series Ethernet Switches Operation Manual Login Huawei Technologies Proprietary ...
Страница 93: ...HUAWEI Quidway S3100 Series Ethernet Switches Operation Manual VLAN Huawei Technologies Proprietary ...
Страница 100: ...HUAWEI Quidway S3100 Series Ethernet Switches Operation Manual Management VLAN Huawei Technologies Proprietary ...
Страница 112: ...HUAWEI Quidway S3100 Series Ethernet Switches Operation Manual GVRP Huawei Technologies Proprietary ...
Страница 121: ...HUAWEI Quidway S3100 Series Ethernet Switches Operation Manual Port Huawei Technologies Proprietary ...
Страница 134: ...HUAWEI Quidway S3100 Series Ethernet Switches Operation Manual Link Aggregation Huawei Technologies Proprietary ...
Страница 141: ...HUAWEI Quidway S3100 Series Ethernet Switches Operation Manual Port Isolation Huawei Technologies Proprietary ...
Страница 154: ...HUAWEI Quidway S3100 Series Ethernet Switches Operation Manual MSTP Huawei Technologies Proprietary ...
Страница 201: ...HUAWEI Quidway S3100 Series Ethernet Switches Operation Manual 802 1x Huawei Technologies Proprietary ...
Страница 231: ...HUAWEI Quidway S3100 Series Ethernet Switches Operation Manual AAA RADIUS Huawei Technologies Proprietary ...
Страница 275: ...HUAWEI Quidway S3100 Series Ethernet Switches Operation Manual ARP Huawei Technologies Proprietary ...
Страница 284: ...HUAWEI Quidway S3100 Series Ethernet Switches Operation Manual DHCP Snooping Huawei Technologies Proprietary ...
Страница 289: ...HUAWEI Quidway S3100 Series Ethernet Switches Operation Manual ACL Huawei Technologies Proprietary ...
Страница 300: ...HUAWEI Quidway S3100 Series Ethernet Switches Operation Manual QoS Huawei Technologies Proprietary ...
Страница 326: ...HUAWEI Quidway S3100 Series Ethernet Switches Operation Manual IGMP Snooping Huawei Technologies Proprietary ...
Страница 345: ...HUAWEI Quidway S3100 Series Ethernet Switches Operation Manual Stack Cluster Huawei Technologies Proprietary ...
Страница 367: ...HUAWEI Quidway S3100 Series Ethernet Switches Operation Manual SNMP Huawei Technologies Proprietary ...
Страница 378: ...HUAWEI Quidway S3100 Series Ethernet Switches Operation Manual RMON Huawei Technologies Proprietary ...
Страница 386: ...HUAWEI Quidway S3100 Series Ethernet Switches Operation Manual NTP Huawei Technologies Proprietary ...
Страница 410: ...HUAWEI Quidway S3100 Series Ethernet Switches Operation Manual SSH2 0 Huawei Technologies Proprietary ...
Страница 432: ...HUAWEI Quidway S3100 Series Ethernet Switches Operation Manual File System Management Huawei Technologies Proprietary ...
Страница 444: ...HUAWEI Quidway S3100 Series Ethernet Switches Operation Manual FTP and TFTP Huawei Technologies Proprietary ...
Страница 459: ...HUAWEI Quidway S3100 Series Ethernet Switches Operation Manual Information Center Huawei Technologies Proprietary ...
Страница 510: ...HUAWEI Quidway S3100 Series Ethernet Switches Operation Manual Appendix Huawei Technologies Proprietary ...