select-authentication-domain

Function

The select-authentication-domain individual command configures a device to use the domain carried in an EAP user name as the authentication domain for an EAP-authentication-based RADIUS proxy user.

The undo select-authentication-domain individual command cancels the configuration.

By default, the default authentication domain configured for a BAS interface is used as the authentication domain for an EAP-authentication-based RADIUS proxy user.

This command is supported only on the NetEngine 8000 F1A.

Format

select-authentication-domain individual

undo select-authentication-domain individual

Parameters

None

Views

BAS interface view

Default Level

2: Configuration level

Task Name and Operations

Task Name Operations
bras-control write

Usage Guidelines

Usage Scenario

In the scenario where EAP-authentication-based and web-authentication-based RADIUS proxy users go online from the same BAS interface, the authentication mode configured for the BAS interface is web authentication, and the default authentication domain is web pre-authentication domain. While web-authentication-based RADIUS proxy users are authenticated in the web pre-authentication domain, EAP-authentication-based RADIUS proxy users cannot be authenticated in the web pre-authentication domain. To allow an EAP-authentication-based RADIUS proxy user to be authenticated not in the web pre-authentication domain but in the domain carried in the EAP user name, run the select-authentication-domain individual command.

In the scenario where only EAP-authentication-based RADIUS proxy users exist, to allow an EAP-authentication-based RADIUS proxy user to be authenticated in the domain carried in the EAP user name, run the select-authentication-domain individual command.

Use the domain carried in an EAP user name preferentially.

  • If the domain in the EAP user name does not exist, use the roaming domain configured on the interface.
  • If no domain is included in the EAP user name, use the default authentication domain.

Precautions

In VS mode, this command is supported only by the admin VS.

Example

# Configure the device to use the domain carried in an EAP user name as the authentication domain for an EAP-authentication-based RADIUS proxy user on the BAS interface GE 0/1/9.
<HUAWEI> system-view
[~HUAWEI] interface GigabitEthernet0/1/9
[~HUAWEI-GigabitEthernet0/1/9] bas
[~HUAWEI-GigabitEthernet0/1/9-bas] select-authentication-domain individual
Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
< Previous topic Next topic >