EasyManua.ls Logo

H3C S5100-SI

H3C S5100-SI
830 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Loading...
2-12
As shown in Figure 2-1, NAS 1 and NAS 2 are connected to the same RADIUS server for authentication.
For easy management, the RADIUS server issues the same authorization attributes to all the users.
However, users attached to NAS 1 need these attributes while users attached to NAS 2 do not want to
use the assigned Attribute 28, idle-timeout. You can configure the attribute ignoring function on NAS 2
to ignore Attribute 28.
Figure 2-1 Network diagram for the RADIUS authorization attribute ignoring function
Host 1
Switch
RADIUS server
Host 2
IP network
NAS 1
NAS 2
Follow these steps to configure the RADIUS authorization attribute ignoring function:
To do… Use the command… Remarks
Enter system view
system-view
Create a RADIUS
scheme and enter its
view
radius scheme
radius-scheme-name
Required
By default, a RADIUS scheme named
"system" has already been created in
the system.
Configure the RADIUS
authorization attribute
ignoring function
attribute-ignore { standard
| vendor vendor-id } type
type-value
Required
Disabled by default.
In a RADIUS scheme, you can configure:
z One standard attribute ignoring command
z One proprietary attribute ignoring command per vendor
z Up to three attribute ignoring commands in total
Configuring RADIUS Accounting Servers
Follow these steps to configure RADIUS accounting servers:
To do… Use the command… Remarks
Enter system view
system-view

Table of Contents

Related product manuals