HP 6125XLG R2306-HP 6125XLG Blade Switch Security Configuration Guide - Page 49

Configuring AAA methods for ISP domains, Configuration prerequisites, Creating an ISP domain

Page 49 highlights

Task Display the configuration of LDAP schemes. Command display ldap scheme [ scheme-name ] Configuring AAA methods for ISP domains You configure AAA methods for an ISP domain by referencing configured AAA schemes in ISP domain view. Each ISP domain has a set of system-defined AAA methods, which are local authentication, local authorization, and local accounting. If you do not configure any AAA methods for an ISP domain, the device uses the system-defined AAA methods for users in the domain. Configuration prerequisites To use local authentication for users in an ISP domain, configure local user accounts on the device first. See "Configuring local user attributes." To use remote authentication, authorization, and accounting, create the required RADIUS, HWTACACS, and LDAP schemes as described in "Configuring RADIUS schemes," "Configuring HWTACACS schemes," and "Configuring LDAP schemes." Creating an ISP domain In a networking scenario with multiple ISPs, the device can connect to users of different ISPs, and these users can have different user attributes, such as different username and password structures, different service types, and different rights. To manage users of different ISPs, configure ISP domains, and configure AAA methods and domain attributes for each ISP domain as needed. The device supports up to 16 ISP domains, including the system-defined ISP domain system. You can specify one of the ISP domains as the default domain. On the device, each user belongs to an ISP domain. If a user provides no ISP domain name at login, the device considers the user belongs to the default ISP domain. To delete the ISP domain functioning as the default ISP domain, change it to a non-default ISP domain by using the undo domain default enable command. To create an ISP domain: Step Command 1. Enter system view. system-view 2. Create an ISP domain and enter ISP domain view. domain isp-name 3. Return to system view. quit 4. (Optional.) Specify the default domain default enable ISP domain. isp-name Remarks N/A N/A N/A By default, the default ISP domain is the system-defined ISP domain system. 40

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276

40
Task
Command
Display the configuration of LDAP schemes.
display ldap scheme
[
scheme-name
]
Configuring AAA methods for ISP domains
You configure AAA methods for an ISP domain by referencing configured AAA schemes in ISP domain
view. Each ISP domain has a set of system-defined AAA methods, which are local authentication, local
authorization, and local accounting. If you do not configure any AAA methods for an ISP domain, the
device uses the system-defined AAA methods for users in the domain.
Configuration prerequisites
To use local authentication for users in an ISP domain, configure local user accounts on the device first.
See "
Configuring local user attributes
."
To use remote authentication, authorization, and accounting, create the required RADIUS, HWTACACS,
and LDAP schemes as described in "
Configuring RADIUS schemes
," "
Configuring HWTACACS
schemes
," and "
Configuring LDAP schemes
."
Creating an ISP domain
In a networking scenario with multiple ISPs, the device can connect to users of different ISPs, and these
users can have different user attributes, such as different username and password structures, different
service types, and different rights. To manage users of different ISPs, configure ISP domains, and
configure AAA methods and domain attributes for each ISP domain as needed.
The device supports up to 16 ISP domains, including the system-defined ISP domain
system
. You can
specify one of the ISP domains as the default domain.
On the device, each user belongs to an ISP domain. If a user provides no ISP domain name at login, the
device considers the user belongs to the default ISP domain.
To delete the ISP domain functioning as the default ISP domain, change it to a non-default ISP domain by
using the
undo domain
default
enable
command.
To create an ISP domain:
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Create an ISP domain and
enter ISP domain view.
domain
isp-name
N/A
3.
Return to system view.
quit
N/A
4.
(Optional.) Specify the default
ISP domain.
domain default enable
isp-name
By default, the default ISP domain is the
system-defined ISP domain
system
.