R3166-R3206-HP High-End Firewalls Access Control Configuration Guide-6PW101

131
To do… Use the command… Remarks
Set the guest attribute for the user group
group-attribute allow-guest
Optional
By default, the guest
attribute is not set for a
user group, and guest
users created by a guest
manager through the
web interface cannot
join the group.
Displaying and maintaining local users and local user groups
To do… Use the command… Remarks
Display local user information
display local-user [ service-type { ftp |
portal | ppp | ssh | telnet | terminal }
| state { active | block } | user-name
user-name ]
Available in any view
Display the user group configuration
information
display user-group [ group-name ] Available in any view
Configuring RADIUS schemes in the web interface
A RADIUS scheme specifies the RADIUS servers that the device can cooperate with and defines a set of
parameters that the device uses to exchange information with the RADIUS servers. There may be
authentication/authorization servers and accounting servers, or primary servers and secondary servers.
The parameters include the IP addresses of the servers, the shared keys, and the RADIUS server type.
Configuration task list
NOTE:
The RADIUS scheme configured through the Web interface is named system.
By default, there is no RADIUS scheme named system in the system. When you select any item under User >
RADIUS from the navigation tree to enter the page of the item, the system will automatically create a scheme
named system.
Table 46 lists the RADIUS configuration steps:
Table 46 RADIUS configuration steps
Task Remarks
Configuring RADIUS server
Authentication server is mandatory and accounting server is optional.
This section describes how to specify the primary and the secondary RADIUS
authentication/accounting servers.
By default, no server is specified.
Configuring RADIUS
parameters
Optional
This section describes how to configure the parameters that are necessary for
information exchange between the device and RADIUS server.