Verifying the Local Authentication and Authorization Configuration
Procedure
- Run the display aaa configuration command to check the AAA summary.
- Run the display authentication-scheme [ authentication-scheme-name ] command to verify the authentication scheme configuration.
- Run the display authorization-scheme [ authorization-scheme-name ] command to verify the authorization scheme configuration.
- To verify information about access users, run the following commands:
- display access-user [ domain domain-name | interface interface-type interface-number [ vlan vlan-id [ qinq qinq-vlan-id ] ] | ip-address ip-address [ vpn-instance vpn-instance-name ] | ipv6-address ipv6-address | access-slot slot-id | wired | wireless ] [ detail ]
- display access-user username user-name [ detail ]
- display access-user ssid ssid-name (This command is supported only by the S5730-HI, S5731-H, S5731S-H, S6730-H, S6730S-H, S5732-H, S6720-HI, and S5720-HI.)
- display access-user [ mac-address mac-address | service-scheme service-scheme-name | user-id user-id | statistics ] (The statistics keyword is supported only by the S5730-HI, S5731-H, S5731S-H, S6730-H, S6730S-H, S5732-H, S6720-HI, and S5720-HI.)
- display access-user access-type { admin [ ftp | ssh | telnet | terminal | web ] | ppp } [ username user-name ]
- Run the display domain [ name domain-name ] command to verify the domain configuration.
- Run the display local-user [ domain domain-name | state { active | block } | username username ] * command to check the brief information about local users.
- Run the display local-aaa-user password policy { access-user | administrator } command to display the password policy for local users.
- Run the display local-user expire-time command to verify the time when the local account expires.
- Run the display aaa statistics access-type-authenreq command to verify the number of authentication requests.
- Run the display access-user user-name-table statistics { all | username username } command to check statistics on users who are allowed to access the network using the user name.