authening authen-fail

Function

The authening authen-fail command configures a policy to be adopted after user authentication fails.

The undo authening authen-fail command restores the default setting.

By default, a user goes offline after an authentication failure.

This command is supported only on the NetEngine 8000 F1A.

Format

authening authen-fail { offline | online authen-domain domain-name }

undo authening authen-fail

Parameters

Parameter Description Value
offline

Forces the users failing authentication to go offline.

-

online

Allows users failing authentication to remain online.

-

authen-domain domain-name

Specifies a domain that is used for controlling the access right of a user who fails authentication but remains online. This domain is created through the domain domain-name command. This domain must exist. Commonly, a UCL is configured in this domain to control the access right of a user.

The name of this domain is a string of 1 to 64 characters.

Views

Authentication scheme view

Default Level

2: Configuration level

Task Name and Operations

Task Name Operations
aaa-access write

Usage Guidelines

Usage Scenario

The authening authen-fail command, you can make a user to go offline or redirect a user to a domain with limited rights, such as a domain which can access only the intranet and cannot access the Internet, when this user fails authentication. The authening authen-redirect online authen-domain command, you can redirect a user to a domain with limited rights when the user quota is used up.

Precautions

In VS mode, this command is supported only by the admin VS.

Example

# Configure the policy for authentication failures in authentication scheme a1 as online.
<HUAWEI> system-view
[~HUAWEI] aaa
[~HUAWEI-aaa] authentication-scheme a1
[*HUAWEI-aaa-authen-a1] commit
[~HUAWEI-aaa-authen-a1] authening authen-fail online authen-domain default0
Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
< Previous topic Next topic >