Configuring Local Authentication Servers
The AAA local authentication server enables the E Series router to provide local PAP
and CHAP user authentication for subscribers. The router also provides limited
authorization, using the IP address, IP address pool, and operational virtual router
parameters. When a subscriber logs on to the E Series router that is using local
authentication, the subscriber is authenticated against user entries in a local user
database; the optional parameters are assigned to subscribers after the subscriber
is authenticated.
Creating the Local Authentication Environment
To create your local authentication environment:
1.
Create local user databases—Create the default database or a named database.
2.
Add entries to local user databases—Add user entries to the database. A database
can contain information for multiple users.
3.
Assign a local user database to the virtual router—Specify the database that the
virtual router will use to authenticate subscribers.
4.
Enable local authentication on the virtual router—Specify the
local
method as
an AAA authentication method used by the virtual router.
Creating Local User Databases
When a subscriber connects to an E Series router that is using local authentication,
the local authentication server uses the entries in the local user database selected by
the virtual router to authenticate the subscriber.
A local authentication server can have multiple local user databases, and each
database can have entries for multiple subscribers. The default local user database,
if it exists, is used for local authentication by default. The E Series router supports a
maximum of 100 user entries. A maximum of 100 databases can be configured.
To create a local user database, use the
aaa local database
command and the name
of the database; use the name
default
to create the default local user database:
host1(config)#
aaa local database westLocal40
Adding User Entries to Local User Databases
The local authentication server uses the information in a local user database to
authenticate a subscriber. A local user database can contain information for multiple
users.
The E Series router provides two commands for adding entries to local user databases:
the
username
command and the
aaa local username
command. You can specify
the following parameters:
40
■
Configuring Local Authentication Servers
JUNOSe 11.0.x Broadband Access Configuration Guide
Содержание JUNOSE 11.0.X MULTICAST ROUTING
Страница 6: ...vi...
Страница 28: ...xxviii Table of Contents JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 36: ...xxxvi List of Tables JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 42: ...2 Managing Remote Access JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 204: ...164 Managing RADIUS and TACACS JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 274: ...234 CLI Commands Used to Modify RADIUS Attributes JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 292: ...252 Monitoring RADIUS Relay Server JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 336: ...296 RADIUS Client Terminate Reasons JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 368: ...328 Managing L2TP JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 408: ...368 Configuring the Weighted Load Balancing Method JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 444: ...404 PPP Accounting Statistics JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 492: ...452 Monitoring Operational Status within the Current VR Context JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 494: ...454 Managing DHCP JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 510: ...470 DHCP Local Server Configuration Tasks JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 528: ...488 Configuring the Router to Work with the SRC Software JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 556: ...516 Configuring DHCP Relay Proxy JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 616: ...576 Managing the Subscriber Environment JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 632: ...592 Subscriber Management Configuration Examples JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 636: ...596 Monitoring Active IP Subscribers Created by Subscriber Management JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 672: ...632 Monitoring Active IP Subscribers Created by Subscriber Management JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 674: ...634 Managing Subscriber Services JUNOSe 11 0 x Broadband Access Configuration Guide...
Страница 767: ...Part 7 Index Index on page 729 Index 727...
Страница 768: ...728 Index JUNOSe 11 0 x Broadband Access Configuration Guide...