3Com Switch 8800 Configuration Guide Chapter 40 AAA and RADIUS/TACACS+ Protocol Con
figuration
40-7
Switch 8800 ISP domain view, you can configure a complete set of exclusive ISP
domain attributes on a per-ISP domain basis, which includes AAA policy ( RADIUS
scheme applied etc.)
For the Switch 8800, each supplicant belongs to an ISP domain. Up to 16 domains can
be configured in the system. If a user has not reported its ISP domain name, the system
will put it into the default domain.
Perform the following configuration in system view.
Table 40-2 Create/Delete an ISP domain
Operation Command
Create ISP domain or enter the view of a
specified domain domain isp-name
Remove a specified ISP domain undo domain isp-name
Enable the default ISP domain specified by
isp-name domain default enable isp-name
Restore the default ISP domain to “system” domain default disable
By default, a domain named “system” has been created in the system. The attributes of
“system” are all default values.
40.2.2 Configuring Relevant Attributes of an ISP Domain
The relevant attributes of ISP domain include the adopted RADIUS scheme, ISP
domain state, maximum number of supplicants, accounting optional enable/disable
state, address pool definition, IP address assignment for PPP domain users, and user
idle-cut enable/disable state where:
z The adopted RADIUS scheme is the one used by all the users in the ISP domain.
The RADIUS scheme can be used for RADIUS authentication or accounting. By
default, the default RADIUS scheme is used. The command shall be used
together with the commands of setting RADIUS server and server cluster. For
details, refer to the following Configuring RADIUS section of this chapter. If local is
configured as the first scheme, only the local scheme will be adopted, neither
RADIUS nor TACACS+ scheme will be adopted. When local scheme is adopted,
only authentication and authorization will be performed, accounting will not be
performed. None has the same effect as local. The usernames used for local
authentication carry no domain name, so if the local scheme is configured, pay
attention not to add domain name to the username when you configure a local
user.
z Every ISP domain has two states: active and block. If an ISP domain is in active
state, the users in it are allowed to request network services, while in block state,
its users are inhibit from requesting any network service, which will not affect the