HP VPN Firewall Appliances Access Control Command Reference

Table Of Contents
151
Views
ISP domain view
Default command level
2: System level
Parameters
local: Performs local authorization.
none: Does not perform any authorization exchange. In this case, an authenticated LAN user can access
the network directly.
radius-scheme radius-scheme-name: Specifies a RADIUS scheme by its name, a case-insensitive string of
1 to 32 characters.
Usage guidelines
The specified RADIUS scheme must already exist.
The RADIUS authorization configuration takes effect only when the authentication method and
authorization method of the ISP domain use the same RADIUS scheme.
The following matrix shows the authorization dvpn command and firewalls and firewall modules
compatibility:
Hardware Command com
p
atible
F1000-A-EI/F1000-S-EI No
F1000-E Yes
F5000 Yes
F5000-S/F5000-C Yes
VPN firewall modules Yes
20-Gbps VPN firewall modules No
Examples
# Configure ISP domain test to use local authorization for DVPN users.
<Sysname> system-view
[Sysname] domain test
[Sysname-isp-test] authorization dvpn local
# Configure ISP domain test to use RADIUS authorization scheme rd for DVPN users and use local
authorization as the backup.
<Sysname> system-view
[Sysname] domain test
[Sysname-isp-test] authorization dvpn radius-scheme rd local
Related commands
local-user
authorization default
radius scheme