AAA Configuration
175
CAUTION:
■
On an S4200G series switch, each access user belongs to an ISP domain. You can
configure up to 16 ISP domains on the switch. When a user logs in, if no ISP
domain name is carried in the user name, the switch assumes that the user
belongs to the default ISP domain.
■
When charging a user, if the system does not find any available accounting server
or fails to communicate with any accounting server, it will not disconnect the user
as long as the
accounting optional
command has been executed.
■
The self-service server location function must cooperate with a
self-service-supported RADIUS server (such as CAMS). Through self-service, users
can manage and control their accounts or card numbers by themselves. A server
installed with the self-service software is called a self-service server.
3Com's CAMS Server is a service management system used to manage networks and
secure networks and user information. Cooperating with other network devices (such
as switches) in a network, the CAMS Server implements the AAA (authentication,
authorization and accounting) services and rights management
Configuring an AAA
Scheme for an ISP
Domain
You can configure an AAA scheme in one of the following two ways:
Configuring a bound AAA scheme
You can use the
scheme
command to specify an AAA scheme. If you specify a
RADIUS scheme, the authentication, authorization and accounting will be uniformly
implemented by the RADIUS server specified in the RADIUS scheme. In this way, you
can specify only one scheme to implement all the three AAA functions and do not
need to specify different schemes for authentication, authorization and accounting
respectively
CAUTION:
You can execute the
scheme
command with the radius-scheme-name
argument to adopt an already configured RADIUS scheme to implement all the three
AAA functions. If you adopt the local scheme, only the authentication and
authorization functions are implemented, the accounting function cannot be
implemented.
■
If you execute the
scheme
radius-scheme
radius-scheme-name
local
command,
the local scheme becomes the secondary scheme in case the RADIUS server does
not response normally. That is, if the communication between the switch and the
RADIUS server is normal, no local authentication is performed; otherwise, local
authentication is performed.
Table 137
Configure a bound AAA scheme
Operation
Command
Description
Enter system view
system-view
-
Create an ISP domain
or enter the view of an
existing ISP domain
domain
isp-name
Required
Configure an AAA
scheme for the ISP
domain
scheme
{ local | none |
radius-scheme
radius-scheme-name
[
local ]
}
Required
By default, the ISP domain uses the
local
AAA scheme.
Configure an RADIUS
scheme for the ISP
domain
radius-scheme
radius-scheme-name
Optional
This command has the same effect as the
scheme radius-scheme
command.
Summary of Contents for 4200G 12-Port
Page 10: ...8 CONTENTS...
Page 14: ...4 ABOUT THIS GUIDE...
Page 46: ...32 CHAPTER 5 LOGGING IN THROUGH WEB BASED NETWORK MANAGEMENT SYSTEM...
Page 48: ...34 CHAPTER 6 LOGGING IN THROUGH NMS...
Page 60: ...46 CHAPTER 9 VLAN CONFIGURATION...
Page 64: ...50 CHAPTER 10 MANAGEMENT VLAN CONFIGURATION...
Page 80: ...66 CHAPTER 13 GVRP CONFIGURATION...
Page 98: ...84 CHAPTER 15 LINK AGGREGATION CONFIGURATION...
Page 112: ...98 CHAPTER 18 MAC ADDRESS TABLE MANAGEMENT...
Page 126: ...112 CHAPTER 19 LOGGING IN THROUGH TELNET...
Page 162: ...148 CHAPTER 20 MSTP CONFIGURATION...
Page 274: ...260 CHAPTER 29 IGMP SNOOPING CONFIGURATION...
Page 276: ...262 CHAPTER 30 ROUTING PORT JOIN TO MULTICAST GROUP CONFIGURATION...
Page 298: ...284 CHAPTER 33 SNMP CONFIGURATION...
Page 304: ...290 CHAPTER 34 RMON CONFIGURATION...
Page 338: ...324 CHAPTER 36 SSH TERMINAL SERVICES...
Page 356: ...342 CHAPTER 38 FTP AND TFTP CONFIGURATION...
Page 365: ...Information Center Configuration Example 351 S4200G terminal logging...
Page 366: ...352 CHAPTER 39 INFORMATION CENTER...
Page 378: ...364 CHAPTER 40 BOOTROM AND HOST SOFTWARE LOADING...
Page 384: ...370 CHAPTER 41 Basic System Configuration and Debugging...
Page 388: ...374 CHAPTER 43 NETWORK CONNECTIVITY TEST...
Page 406: ...392 CHAPTER 45 CONFIGURATION OF NEWLY ADDED CLUSTER FUNCTIONS...