H3C S7500 Series Ethernet Switches Command Manual

Table Of Contents
Command Manual – AAA & RADIUS & HWTACACS & EAD
H3C S7500 Series Ethernet Switches
Chapter 1 AAA & RADIUS & HWTACACS
Configuration Commands
1-10
The default ISP domain is system
An ISP domain is an ISP user group comprising the users of the same ISP. Normally, in
a username (such as gw20010608@aabbcc.net) in the userid@isp-name format,
isp-name (such as aabbcc.net in the above example) after "@" is the name of the ISP
domain. When implementing access control, for ISP users with the name format
userid@isp-name, an H3C series Ethernet switch uses userid as the username for
authentication and uses isp-name as domain name.
ISP domains are intended to support a multi-ISP application environment where an
access device may be accessed by users of different ISPs. The user attributes, such as
username/password composition and service type/privilege, of ISP users may vary.
Therefore, it is necessary to distinguish between them by setting ISP domains. You can
configure a complete set of independent ISP domain attributes, including AAA schemes
(such as the RADIUS scheme used), for each ISP domain in ISP domain view.
For the switch, each access user belongs to an ISP domain.
You can configure up to 16 ISP domains in the system. If the specified ISP domain does
not exist when you issue this command, the system creates a new ISP domain. An ISP
domain is active immediately after being created.
Related commands: access-limit, scheme, state, display domain
Examples
# Create an ISP domain named aabbcc.net and enter its view.
[H3C] domain aabbcc.net
New Domain added.
[H3C-isp-aabbcc.net]
1.1.8 idle-cut
Syntax
idle-cut { disable | enable minute flow }
View
ISP domain view
Parameters
disable: Inhibits users from enabling the idle-cut function.
enable: Allows users to enable the idle-cut function.
minute: Maximum idle time, ranging from 1 minute to 120 minutes.
flow: Minimum data flow, ranging from 1 byte to 10,240,000 bytes (10 M).