HP VPN Firewall Appliances Access Control Command Reference

Table Of Contents
155
authorization default
hwtacacs scheme
radius scheme
authorization ssl-vpn
Use authorization ssl-vpn to configure the authorization method for SSL VPN users.
Use undo authorization ssl-vpn to restore the default.
Syntax
authorization ssl-vpn radius-scheme radius-scheme-name
undo authorization ssl-vpn
Default
The default authorization method for the ISP domain is used for SSL VPN users.
Views
ISP domain view
Default command level
2: System level
Parameters
radius-scheme radius-scheme-name: Specifies a RADIUS scheme by its name, a case-insensitive string of
1 to 32 characters.
Usage guidelines
The specified RADIUS scheme must already exist.
The RADIUS authorization configuration takes effect only when the authentication method and
authorization method of the ISP domain use the same RADIUS scheme.
The following matrix shows the authorization ssl-vpn command and firewalls and firewall modules
compatibility:
Hardware Command com
p
atible
F1000-A-EI/F1000-S-EI Yes
F1000-E Yes
F5000 No
F5000-S/F5000-C Yes
VPN firewall modules No
20-Gbps VPN firewall modules No
Examples
# Configure ISP domain test to use RADIUS authorization scheme rd for SSL VPN users.
<Sysname> system-view
[Sysname] domain test
[Sysname-isp-test] authorization ssl-vpn radius-scheme rd