F3215-HP Load Balancing Module Security Command Reference-6PW101

42
Usage guidelines
After you configure the accounting optional command for a domain, a user who would otherwise be
disconnected can continue to use the network resources when no accounting server is available or when
communication with the current accounting server fails. However, the device no longer sends real-time
accounting updates for the user. The accounting optional feature applies to scenarios where accounting
is not important.
After you configure the accounting optional command, the setting configured by the access-limit
command in local user view has no effect.
Examples
# Enable the accounting optional feature for users in domain test.
<Sysname> system-view
[Sysname] domain test
[Sysname-isp-test] accounting optional
authentication default
Use authentication default to configure the default authentication method for an ISP domain.
Use undo authentication default to restore the default.
Syntax
authentication default { hwtacacs-scheme hwtacacs-scheme-name [ local ] | local | none |
radius-scheme radius-scheme-name [ local ] }
undo authentication default
Default
The default authentication method of an ISP domain is local.
Views
ISP domain view
Default command level
2: System level
Parameters
hwtacacs-scheme hwtacacs-scheme-name: Specifies an HWTACACS scheme by its name, a
case-insensitive string of 1 to 32 characters.
local: Performs local authentication.
none: Does not perform any authentication.
radius-scheme radius-scheme-name: Specifies a RADIUS scheme by its name, a case-insensitive string of
1 to 32 characters.
Usage guidelines
The specified RADIUS or HWTACACS scheme must have been configured.
The default authentication method is used for all users who support the specified authentication method
and have no specific authentication method configured.