9
Parameters
hwtacacs-scheme hwtacacs-scheme-name: Specifies an HWTACACS scheme by its name, a
case-insensitive string of 1 to 32 characters.
local: Performs local accounting.
none: Does not perform accounting.
radius-scheme radius-scheme-name: Specifies a RADIUS scheme by its name, a case-insensitive string of
1 to 32 characters.
Usage guidelines
You can specify one primary accounting method and multiple backup accounting methods.
When the primary method is invalid, the device attempts to use the backup methods in sequence. For
example, the accounting ppp radius-scheme radius-scheme-name local none command specifies a
primary RADIUS accounting method and two backup methods (local accounting and no accounting).
The device performs RADIUS accounting by default and performs local accounting when the RADIUS
server is invalid. The device does not perform accounting when both of the previous methods are invalid.
Examples
# Configure ISP domain test to use local accounting for PPP users.
<Sysname> system-view
[Sysname] domain test
[Sysname-isp-test] accounting ppp local
# Configure ISP domain test to use RADIUS accounting scheme rd for PPP users and use local accounting
as the backup.
<Sysname> system-view
[Sysname] domain test
[Sysname-isp-test] accounting ppp radius-scheme rd local
Related commands
• accounting default
• hwtacacs scheme
• local-user
• radius scheme
authentication default
Use authentication default to specify the default authentication method for an ISP domain.
Use undo authentication default to restore the default.
Syntax
In non-FIPS mode:
authentication default { hwtacacs-scheme hwtacacs-scheme-name [ radius-scheme
radius-scheme-name ] [ local ] [ none ] | ldap-scheme ldap-scheme-name [ local ] [ none ] | local [ none ]
| none | radius-scheme radius-scheme-name [ hwtacacs-scheme hwtacacs-scheme-name ] [ local ]
[ none ] }
undo authentication default
In FIPS mode: