Info: Create a new domain
huawei(config-aaa-domain-isp)#
authentication-scheme newscheme
huawei(config-aaa-domain-isp)#
quit
huawei(config-aaa)#
local-user user1 password a123456
3.12.2 Configuring the Remote AAA (Based on the RADIUS
Protocol)
The MA5616 is interconnected with the RADIUS server through the RADIUS protocol to
implement authentication and accounting.
Context
l
What is RADIUS:
–
Radius is short for the remote authentication dial-in user service. It is a distributed
information interaction protocol with the client-server structure. Generally, it is used to
manage a large number of distributed dial-in users.
–
Radius implements the user accounting by managing a simple user database.
–
The authentication and accounting requests of users can be passed on to the Radius
server through a network access server (NAS).
l
Working principles of RADIUS:
–
When a user tries to access another network (or some network resources) by setting up
a connection to the NAS through a network, the NAS forwards the user authentication
and accounting information to the RADIUS server. The RADIUS protocol specifies the
means of transmitting the user information and accounting information between the
NAS and the RADIUS server.
–
The RADIUS server receives the connection requests of users sent from the NAS,
authenticates the user account and password contained in the user data, and returns the
required data to the NAS.
l
Specification:
–
For the MA5616, the RADIUS is configured based on each RADIUS server group.
–
In actual networking, a RADIUS server group can be any of the following:
–
An independent RADIUS server
–
A pair of primary/secondary RADIUS servers with the same configuration but
different IP addresses
–
The following lists the attributes of a RADIUS server template:
–
IP addresses of primary and secondary servers
–
Shared key
–
RADIUS server type
l
The configuration of the RADIUS protocol defines only the essential parameters for the
information exchange between the MA5616 and the RADIUS server. To make the essential
parameters take effect, the RADIUS server group should be referenced in a certain domain.
Procedure
Step 1
Configure the authentication scheme.
SmartAX MA5616 Multi-service Access Module
Configuration Guide
3 Basic Configuration
Issue 04 (2011-10-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
97