234CHAPTER 7: AAA COMMANDS

set authentication Configures an authentication rule to grant network access to a user who

last-resortis not otherwise granted or denied access by 802.1X, or granted access by MAC authentication.

Syntax set authentication last-resort

{ssid ssid-name wired} method1 [method2] [method3] [method4]

„ssid ssid-name— SSID name to which this authentication rule applies. To apply the rule to all SSIDs, type any.

„wired — Applies this authentication rule specifically to users connected to a wired authentication port.

„method1, method2, method3, method4 — At least one of up to four methods that MSS uses to handle authentication. Specify one or more of the following methods in priority order. MSS applies multiple methods in the order you enter them.

A method can be one of the following:

„local — Uses the local database of usernames and user groups on the WX switch for authentication.

„server-group-name— Uses the defined group of RADIUS servers for authentication. You can enter up to four names of existing RADIUS server groups as methods.

For more information, see “Usage.”

Defaults — By default, authentication is unconfigured for all clients with network access through MAP ports or wired authentication ports on the WX switch. Connection, authorization, and accounting are also disabled for these users. When using RADIUS for authentication, a last-resort user’s default authorization password is 3Com.

Access — Enabled.

History —Introduced in MSS Version 3.0.

Usage — You can configure different authentication methods for different groups of users by “globbing.” (For details, see “User Globs” on page 26.)

Page 234
Image 234
HP Manager Software manual Syntax set authentication last-resort