< Home

Verifying the Policy Association Configuration

Context

You can run the following commands to check the configurations on authentication access devices and authentication control devices.

Procedure

  • Run the display associate-user command to check the user association information on the device.

    This command applies to authentication access devices and authentication control devices.

  • Run the display access-user as-name as-name command to view information about online users on a specified authentication access device.

    This command applies only to authentication control devices.

    The actual name of an authentication access device may differ from the name displayed on the authentication control device (using the display as all command). When an authentication access device goes online, its name is processed as follows:
    • If the authentication access device uses the default name, its name is changed to default name-MAC address of the authentication access device on the authentication control device.
    • If the authentication access device name contains spaces or double quotation masks ("), the spaces are changed to hyphens (-) and the double quotation masks (") are changed to single quotation masks (') on the authentication control device.

  • Run the display authentication interface interface-type interface-number command to check whether the remote access control function is enabled on the authentication access device's interface.

    This command displays output only on authentication access devices.

  • Run the display associate-user statistics [ interface interface-type interface-number ] command to view statistics about associated users on the authentication access device's interface.

    This command applies only to authentication access devices.

  • Run the display authentication associate command to view global configurations of associated users.

    This command applies only to authentication access devices.

  • Run the display authentication associate alarm-restrain-table { all | interface interface-type interface-number } command to view suppression table information of alarms that are generated due to excess associated users.

    This command applies only to authentication access devices.

  • Run the display access-user arp-detect control-point mac-ip command to check whether the source IP address and source MAC address of detection packets sent by an AS are configured to be the same as those used by an authentication control device for detection.

    This command applies only to authentication control devices.

Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
< Previous topic