The select-authentication-domain individual command configures a device to use the domain carried in an EAP user name as the authentication domain for an EAP-authentication-based RADIUS proxy user.
The undo select-authentication-domain individual command cancels the configuration.
By default, the default authentication domain configured for a BAS interface is used as the authentication domain for an EAP-authentication-based RADIUS proxy user.
This command is supported only on the NetEngine 8000 F1A.
Usage Scenario
In the scenario where EAP-authentication-based and web-authentication-based RADIUS proxy users go online from the same BAS interface, the authentication mode configured for the BAS interface is web authentication, and the default authentication domain is web pre-authentication domain. While web-authentication-based RADIUS proxy users are authenticated in the web pre-authentication domain, EAP-authentication-based RADIUS proxy users cannot be authenticated in the web pre-authentication domain. To allow an EAP-authentication-based RADIUS proxy user to be authenticated not in the web pre-authentication domain but in the domain carried in the EAP user name, run the select-authentication-domain individual command.
In the scenario where only EAP-authentication-based RADIUS proxy users exist, to allow an EAP-authentication-based RADIUS proxy user to be authenticated in the domain carried in the EAP user name, run the select-authentication-domain individual command. Use the domain carried in an EAP user name preferentially.Precautions
In VS mode, this command is supported only by the admin VS.
<HUAWEI> system-view [~HUAWEI] interface GigabitEthernet0/1/9 [~HUAWEI-GigabitEthernet0/1/9] bas [~HUAWEI-GigabitEthernet0/1/9-bas] select-authentication-domain individual