R211x-HP Flexfabric 11900 Security Command Reference

Table Of Contents
11
Predefined user roles
network-admin
mdc-admin
Parameters
hwtacacs-scheme hwtacacs-scheme-name: Specifies an HWTACACS scheme by its name, a
case-insensitive string of 1 to 32 characters.
radius-scheme radius-scheme-name: Specifies a RADIUS scheme by its name, a case-insensitive string of
1 to 32 characters.
Usage guidelines
You can specify one authentication method and one backup authentication method to use in case that
the previous authentication method is invalid.
If you specify a scheme to provide the method for user role authentication, the method applies only to
users whose user role is in the format of level-n.
If an HWTACACS scheme is specified, the device uses the entered username for role authentication.
The username must already exist on the HWTACACS server to represent the highest user level that
a user can obtain. For example, to obtain a level-3 user role whose username is test, the device uses
test@domain-name or test for role authentication, depending on whether the domain name is
required.
If a RADIUS scheme is specified, the device uses the username $enabn$ on the RADIUS server for
role authentication of any usernames, where n is the same as that in the target user role. For
example, to obtain a level-3 user role, the device uses $enab3$@domain-name or $enab3$,
depending on whether the domain name is required.
Examples
# Configure ISP domain test to use HWTACACS scheme tac for user role authentication.
<Sysname> system-view
[Sysname] super authentication-mode scheme
[Sysname] domain test
[Sysname-domain-test] authentication super hwtacacs-scheme tac
Related commands
authentication default
hwtacacs scheme
radius scheme
authorization command
Use authorization command to specify the command authorization method.
Use undo authorization command to restore the default.
Syntax
In non-FIPS mode:
authorization command { hwtacacs-scheme hwtacacs-scheme-name [ local ] [ none ] | local [ none ] |
none }
undo authorization command