Configuring AAA and RADIUS 535

Configuring an

Authentication Method

List for PPP Users

methods the subsequent methods can be used. If authentication again, the authentication is terminated. The none method is meaningful only when it is the last item of the method list. Note that only one login method list can be configured, which can use a different name from the previously configured list. The latest configured authentication method list replaces the former one. All the login services using AAA use this method list.

Five legal combinations of the methods are as follows:

aaa authentication-scheme login default none

aaa authentication-scheme login default local

aaa authentication-scheme login default radius

aaa authentication-scheme login default radius none

aaa authentication-scheme login default radius local

Perform the following configuration in system view.

Table 601 Configure PPP Authentication Method List of AAA

Operation

Command

 

 

Configure PPP authentication method list

aaa authentication-scheme ppp {

of AAA

default methods-list } { method1 [

 

method2 ... ] }

 

 

Cancel PPP authentication method list of

undo aaa authentication-scheme ppp {

AAA

default methods-list }

 

 

By default, the method list combination for the PPP login users is aaa authentication-scheme ppp default local.

If users do not define the method methods-list, the executing sequence defined in the default method list (defined by default) is used.

Method here refers to the authentication method. The authentication method includes the following:

radius --- authentication using the RADIUS server

local --- local authentication

none -- access authority to all users without authentication

While configuring the authentication method list, at least one authentication method should be designated. If multiple authentication methods are designated, then in PPP authentication, only when there is no response to the preceding methods, can the subsequent methods be used. If authentication fails after the preceding methods are used, then the authentication is terminated. The none method is meaningful only when it is the last item of the method list.

There are five legal combinations of the methods:

aaa authentication-scheme ppp default none

aaa authentication-scheme ppp default local

aaa authentication-scheme ppp default radius

aaa authentication-scheme ppp default radius none

Page 539
Image 539
3Com 10014299 Configuring an Authentication Method List for PPP Users, Configure PPP Authentication Method List of AAA