9 
Parameters 
hwtacacs-scheme hwtacacs-scheme-name: Specifies an HWTACACS scheme by its name, a 
case-insensitive string of 1 to 32 characters. 
local: Performs local accounting. 
none: Does not perform accounting. 
radius-scheme radius-scheme-name: Specifies a RADIUS scheme by its name, a case-insensitive string of 
1 to 32 characters. 
Usage guidelines 
You can specify one primary accounting method and multiple backup accounting methods. 
When the primary method is invalid, the device attempts to use the backup methods in sequence. For 
example, the accounting ppp radius-scheme  radius-scheme-name  local  none command specifies a 
primary RADIUS accounting method and two backup methods (local accounting and no accounting). 
The device performs RADIUS accounting by default and performs local accounting when the RADIUS 
server is invalid. The device does not perform accounting when both of the previous methods are invalid. 
Examples 
# Configure ISP domain test to use local accounting for PPP users. 
<Sysname> system-view 
[Sysname] domain test 
[Sysname-isp-test] accounting ppp local 
# Configure ISP domain test to use RADIUS accounting scheme rd for PPP users and use local accounting 
as the backup. 
<Sysname> system-view 
[Sysname] domain test 
[Sysname-isp-test] accounting ppp radius-scheme rd local 
Related commands 
•  accounting default 
•  hwtacacs scheme 
•  local-user 
•  radius scheme 
authentication default 
Use authentication default to specify the default authentication method for an ISP domain. 
Use undo authentication default to restore the default. 
Syntax 
In non-FIPS mode: 
authentication default { hwtacacs-scheme  hwtacacs-scheme-name [ radius-scheme 
radius-scheme-name ] [ local ] [ none ] | ldap-scheme ldap-scheme-name [ local ] [ none ] | local [ none ] 
| none | radius-scheme  radius-scheme-name [ hwtacacs-scheme  hwtacacs-scheme-name ] [ local ] 
[ none ] } 
undo authentication default 
In FIPS mode: