Configuring the Login-Service attribute check method for SSH, FTP, and terminal users

About Login-Service attribute check methods

The device supports the following check methods for the Login-Service attribute (RADIUS attribute 15) of SSH, FTP, and terminal users:

An Access-Accept packet received for a user must contain the matching attribute value. Otherwise, the user cannot log in to the device.

Restrictions and guidelines

Use the loose check method only when the server does not issue Login-Service attribute values 50, 51, and 52 for SSH, FTP, and terminal users.

Procedure

  1. Enter system view.

    system-view

  2. Enter RADIUS scheme view.

    radius scheme radius-scheme-name

  3. Configure the Login-Service attribute check method for SSH, FTP, and terminal users.

    attribute 15 check-mode { loose | strict }

    The default check method is strict.