Users must obtain authorization information before going online. You can configure a user group to manage authorization information about users.
Only the NAC common mode supports authorization by a user group.
Step |
Command |
Remarks |
---|---|---|
Enter the system view. |
system-view | - |
Create a user group and enter the user group view. |
user-group group-name | When using a user group in a dual-link HSB scenario, specify the user group index and ensure that the user group names and user group indexes configured on the active and standby devices are the same. |
Bind an ACL to the user group. |
acl-id acl-number | By default, no ACL is bound to a user group. NOTE:
Before running this command, ensure that the ACL has been created using the acl or acl name command and ACL rules have been configured using the rule command. |
Bind a VLAN to the user group. |
user-vlan vlan-id | By default, no VLAN is bound to a user group. |
Configure the priority of the user group. |
remark { 8021p 8021p-value | dscp dscp-value }* | By default, the priority of a user group is not configured. NOTE:
Only the S5720-EI, S5720-HI, S5730-HI, S5731-H,?S5731S-H, S5731-S, S5731S-S, S6720-HI, S5732-H, S6730-H, S6730S-H, S6730-S, S6730S-S, S6720-EI, and S6720S-EI support this command. |
Limit the rate of traffic from users in the user group. |
car { outbound | inbound } cir cir-value [ pir pir-value | cbs cbs-value | pbs pbs-value ] * | By default, the rate of traffic from users in a user group is not limited. NOTE:
Only the S5720-EI, S5720-HI, S5730-HI, S5731-H,?S5731S-H, S5731-S, S5731S-S, S6720-HI, S5732-H, S6730-H, S6730S-H, S6730-S, S6730S-S, S6720-EI, and S6720S-EI support this command, and the user group CAR can only be applied in the interface outbound direction (outbound) on the S5720-EI, S6720-EI, and S6720S-EI. |
Return to the system view. |
quit | - |
Enable the user group function. |
user-group group-name enable | The user group configuration takes effect only after the user group function is enabled. By default, the user group function is disabled. |