authorization lan-access

Syntax

authorization lan-access { local | none | radius-scheme radius-scheme-name [ local | none ] }

undo authorization lan-access

View

ISP domain view

Default level

2: System level

Parameters

local: Performs local authorization.

none: Does not perform any authorization exchange. In this case, an authenticated LAN user can access the network directly.

radius-scheme radius-scheme-name: Specifies a RADIUS scheme by its name, a case-insensitive string of 1 to 32 characters.

Description

Use authorization lan-access to configure the authorization method for LAN users.

Use undo authorization lan-access to restore the default.

By default, the default authorization method for the ISP domain is used for LAN users.

The specified RADIUS scheme must have been configured.

The RADIUS authorization configuration takes effect only when the authentication method and authorization method of the ISP domain use the same RADIUS scheme.

Related commands: local-user, authorization default, and radius scheme.

Examples

# Configure ISP domain test to use local authorization for LAN users.

<Sysname> system-view
[Sysname] domain test
[Sysname-isp-test] authorization lan-access local

# Configure ISP domain test to use RADIUS authorization scheme rd for LAN users and use local authorization as the backup.

<Sysname> system-view
[Sysname] domain test
[Sysname-isp-test] authorization lan-access radius-scheme rd local