Displaying and maintaining aaa, Aaa configuration examples, Network requirements – H3C Technologies H3C SecPath F1000-E User Manual
Page 226
216
Step Command
Remarks
2.
Create a NAS ID profile and
enter NAS ID profile view.
aaa nas-id profile profile-name
You can apply a NAS ID profile to
an interface enabled with portal.
See "Configuring portal."
3.
Configure a NAS ID-VLAN
binding.
nas-id nas-identifier bind vlan
vlan-id
By default, no NAS ID-VLAN
binding exists.
Displaying and maintaining AAA
Task Command
Remarks
Display the configuration
information of ISP domains.
display domain [ isp-name ] [ | { begin |
exclude | include } regular-expression ]
Available in any view
Display information about user
connections.
display connection [ access-type portal |
domain isp-name | interface interface-type
interface-number | ip ip-address | mac
mac-address | ucibindex ucib-index |
user-name user-name | vlan vlan-id ] [ | { begin
| exclude | include } regular-expression ]
Available in any view
AAA configuration examples
Authentication and authorization for Telnet and SSH users by a
RADIUS server
The RADIUS authentication and authorization configuration for SSH users is similar to that for Telnet users.
This example describes the configuration for Telnet users.
Network requirements
As shown in
, configure SecPath to use the RADIUS server to provide authentication and
authorization services for Telnet users and add an account with the username hello@bbb on the RADIUS
server, so that the Telnet user can log in to SecPath and is authorized with the privilege level 3 after login.
Set the shared keys for secure RADIUS communication to expert, and set the ports for
authentication/authorization and accounting to 1812 and 1813, respectively. Configure SecPath to
include the domain name in the username sent to the RADIUS server.
- H3C SecPath F5000-A5 Firewall H3C SecPath F1000-A-EI H3C SecPath F1000-E-SI H3C SecPath F1000-S-AI H3C SecPath F5000-S Firewall H3C SecPath F5000-C Firewall H3C SecPath F100-C-SI H3C SecPath F1000-C-SI H3C SecPath F100-A-SI H3C SecBlade FW Cards H3C SecBlade FW Enhanced Cards H3C SecPath U200-A U200-M U200-S H3C SecPath U200-CA U200-CM U200-CS