Configuring AAA and RADIUS 535
methods the subsequent methods can be used. If authentication again, the
authentication is terminated. The none method is meaningful only when it is the
last item of the method list. Note that only one login method list can be
configured, which can use a different name from the previously configured list.
The latest configured authentication method list replaces the former one. All the
login services using AAA use this method list.
Five legal combinations of the methods are as follows:
■ aaa authentication-scheme login default none
■ aaa authentication-scheme login default local
■ aaa authentication-scheme login default radius
■ aaa authentication-scheme login default radius none
■ aaa authentication-scheme login default radius local
Configuring an
Authentication Method
List for PPP Users
Perform the following configuration in system view.
Table 601 Configure PPP Authentication Method List of AAA
By default, the method list combination for the PPP login users is aaa
authentication-scheme ppp default local
.
If users do not define the method methods-list, the executing sequence defined in
the default method list (defined by
default) is used.
Method here refers to the authentication method. The authentication method
includes the following:
■ radius --- authentication using the RADIUS server
■ local --- local authentication
■ none -- access authority to all users without authentication
While configuring the authentication method list, at least one authentication
method should be designated. If multiple authentication methods are designated,
then in PPP authentication, only when there is no response to the preceding
methods, can the subsequent methods be used. If authentication fails after the
preceding methods are used, then the authentication is terminated. The none
method is meaningful only when it is the last item of the method list.
There are five legal combinations of the methods:
■ aaa authentication-scheme ppp default none
■ aaa authentication-scheme ppp default local
■ aaa authentication-scheme ppp default radius
■ aaa authentication-scheme ppp default radius none
Operation Command
Configure PPP authentication method list
of AAA
aaa authentication-scheme ppp {
default | methods-list } { method1 [
method2 ... ] }
Cancel PPP authentication method list of
AAA
undo aaa authentication-scheme ppp {
default | methods-list }