The created authentication scheme, authorization scheme, accounting scheme, and HWTACACS server template are in effect only when they are applied to a domain.
The system view is displayed.
The AAA view is displayed.
A domain is created and the domain view is displayed, or the view of an existing domain is displayed.
Procedure |
Command |
Description |
---|---|---|
Apply an authentication scheme to the domain. |
authentication-scheme scheme-name | By default, the authentication scheme default is applied to the default_admin domain, and the authentication scheme named radius is applied to the default domain and other domains. |
Apply an authorization scheme to the domain. |
authorization-scheme authorization-scheme-name | By default, no authorization scheme is applied to a domain. |
Apply an accounting scheme to the domain. |
accounting-scheme accounting-scheme-name | By default, the accounting scheme default is applied to a domain. In this accounting scheme, non-accounting is used and real-time accounting is disabled. |
Procedure |
Command |
Description |
---|---|---|
(Optional) Apply a service scheme to the domain. |
service-scheme service-scheme-name | By default, no service scheme is applied to a domain. |
Apply an HWTACACS server template to the domain. |
hwtacacs-server template-name | By default, no HWTACACS server template is applied to a domain. |
Procedure |
Command |
Description |
---|---|---|
Specify the domain state. |
state { active | block [ time-range time-name &<1–4> ] } | When a domain is in the blocking state, users in this domain cannot log in. By default, a created domain is in the active state. |
Apply a user group to the domain. |
user-group group-name | By default, no user group is applied to a domain. NOTE:
This command is supported only in NAC common mode. |
Procedure |
Command |
Description |
|
---|---|---|---|
AAA view |
Exit from the domain view. | quit | - |
Specify the domain name parsing direction. |
domainname-parse-direction { left-to-right | right-to-left } | The domain name can be parsed from left to right, or from right to left. By default, the domain name is parsed from left to right. |
|
Set the domain name delimiter. |
domain-name-delimiter delimiter | A domain name delimiter can be any of the following: \ / : < > | @ ' %. The default domain name delimiter is @. |
|
Specify the domain name location. |
domain-location { after-delimiter | before-delimiter } | The domain name can be placed before or after the delimiter. By default, the domain name is placed after the domain name delimiter. |
|
Set the security string delimiter. |
security-name-delimiter delimiter | By default, the security string delimiter is * (asterisk). |
|
Authentication profile view |
Exit from the AAA view. |
quit | - |
Create an authentication profile and enter the authentication profile view. |
authentication-profile name authentication-profile-name | By default, the device has six built-in authentication profiles: default_authen_profile, dot1x_authen_profile, mac_authen_profile, portal_authen_profile, dot1xmac_authen_profile, and multi_authen_profile. |
|
Specify the domain name parsing direction. |
domainname-parse-direction { left-to-right | right-to-left } | The domain name can be parsed from left to right, or from right to left. By default, the domain name parsing direction is not specified. |
|
Set the domain name delimiter. |
domain-name-delimiter delimiter | A domain name delimiter can be any of the following: \ / : < > | @ ' %. By default, no domain name delimiter is set. |
|
Specify the domain name location. |
domain-location { after-delimiter | before-delimiter } | By default, the domain name location is not specified. |
|
Set the security string delimiter. |
security-name-delimiter delimiter | By default, no security string delimiter is set. |
Procedure |
Command |
Description |
---|---|---|
Return to the system view. |
quit | - |
Create an authentication profile and enter the authentication profile view. |
authentication-profile name authentication-profile-name | By default, the device has six built-in authentication profiles: default_authen_profile, dot1x_authen_profile, mac_authen_profile, portal_authen_profile, dot1xmac_authen_profile, and multi_authen_profile. |
Specify a permitted domain for wireless users. |
permit-domain name domain-name &<1-4> | By default, no permitted domain is specified for wireless users. After a permitted domain is specified in an authentication profile, only users in the permitted domain can be subject to authentication, authorization, and accounting. |