beautypg.com

H3C Technologies H3C WX3000E Series Wireless Switches User Manual

Page 64

background image

50

Remote authentication (scheme)—The access device cooperates with a RADIUS, HWTACACS, or

LDAP server to authenticate users. Remote authentication features centralized information
management, high capacity, high reliability, and support for centralized authentication service for

multiple access devices. You can configure local or no authentication as the backup method to be

used when the remote server is not available. No authentication can only be configured for LAN

users as the backup method of remote authentication.

You can configure AAA authentication to work alone without authorization and accounting. By default,

an ISP domain uses the local authentication method.
Before configuring authentication methods, complete the following tasks:

For RADIUS, HWTACACS, or LDAP authentication, configure the RADIUS, HWTACACS, or LDAP
scheme to be referenced first. The local and none authentication methods do not require any

scheme.

Determine the access type or service type to be configured. With AAA, you can configure an
authentication method for each access type and service type, limiting the authentication protocols

that can be used for access.

Determine whether to configure an authentication method for all access types or service types.

To configure AAA authentication methods for an ISP domain:

Step Command

Remarks

1.

Enter system view.

system-view

N/A

2.

Enter ISP domain view.

domain isp-name

N/A

3.

Specify the default
authentication method for all

types of users.

authentication default
{ hwtacacs-scheme
hwtacacs-scheme-name [ local ] |

ldap-scheme ldap-scheme-name [ local ]

| local | none | radius-scheme
radius-scheme-name [ local ] }

Optional.
The default setting is local.

4.

Specify the authentication
method for LAN users.

authentication lan-access { local | none
| radius-scheme radius-scheme-name

[ local | none ] }

Optional.
The default authentication

method is used by default.

5.

Specify the authentication
method for login users.

authentication login { hwtacacs-scheme
hwtacacs-scheme-name [ local ] | local
| ldap-scheme ldap-scheme-name

[ local ] | none | radius-scheme

radius-scheme-name [ local ] }

Optional.
The default authentication

method is used by default.

6.

Specify the authentication
method for portal users.

authentication portal { ldap-scheme
ldap-scheme-name [ local ] | local |
none | radius-scheme

radius-scheme-name [ local ] }

Optional.
The default authentication
method is used by default.

7.

Specify the authentication
method for PPP users.

authentication ppp { hwtacacs-scheme
hwtacacs-scheme-name [ local ] | local

| none | radius-scheme
radius-scheme-name [ local ] }

Optional.
The default authentication

method is used by default.

8.

Specify the authentication

method for privilege level
switching.

authentication super { hwtacacs-scheme
hwtacacs-scheme-name |

radius-scheme radius-scheme-name }

Optional.
The default authentication
method is used by default.