< Home

Applying an AAA Scheme to a Domain

Context

The created authentication scheme and HACA server template take effect only after being applied to a domain.

Procedure

  1. Run system-view

    The system view is displayed.

  2. Run aaa

    The AAA view is displayed.

  3. Run domain domain-name

    A domain is created and the domain view is displayed, or the view of an existing domain is displayed.

    The device has two default domains named default and default_admin. The two domains can be modified but not deleted.

  4. Run authentication-scheme authentication-scheme-name

    An authentication scheme is applied to the domain.

    By default, the authentication scheme named radius is applied to the default domain, the authentication scheme named default is applied to the default_admin domain, and the authentication scheme named radius is applied to other domains.

  5. Run accounting-scheme accounting-scheme-name

    An accounting scheme is applied to the domain.

    By default, the accounting scheme named default is applied to a domain. In this default accounting scheme, non-accounting is used and the real-time accounting function is disabled.

  6. Run service-scheme service-scheme-name

    A service scheme is applied to the domain.

    By default, no service scheme is bound to a domain.

  7. Run haca-server template-name

    An HACA server template is applied to the domain.

    By default, no HACA server template is applied to a domain.

  8. (Optional) Run state { active | block [ time-range time-name &<1–4> ] }

    The domain status is configured.

    By default, a domain is in active state after being created. When a domain is in blocking state, users in this domain cannot log in.

Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
< Previous topic Next topic >