Got it

Configure RADIUS on the OLT MA5600T

Created: Jun 30, 2021 09:31:13Latest reply: Jun 30, 2021 09:36:09 449 1 0 0 0
  HiCoins as reward: 0 (problem unresolved)

Hello Community!


Our team encountered the following problems in implementing RADIUS authentication on Huawei OLT MA5600T:

  1. By default, the reported username for RADIUS authentication is with the domain name. You can run the undo radius-server user-name domain-included command to exclude it. After this configuration, whether the domain name needs to be included in the username for logging in to the device?

  2. There are two domains existing on the MA5600T after the Radius authentication is configured: a default domain, and a Huawei domain authenticated by Radius. If the default domain is deleted, does the domain name need to be included in the username for login?

  3. Can the username of RADIUS authentication be displayed by running the display terminal user command?

  4. Why the user authority for Radius authentication is limited and does not support config mode?

  5. Does the OLT support the configuration that the local account can be used only when the user logs in through a serial port but cannot be used when the user logs in remotely?


Can somebody help us?

Thank you!


Featured Answers

Recommended answer

Nino_Chou
Admin Created Jun 30, 2021 09:36:09

Hi, dear friend.


According to the description of your question, the answers are as follows:

  1. Yes, the domain name must be included in the user username for logging in to the device no matter whether the user of RADIUS authentication has configured the username that excludes the domain name by running the undo radius-server user-name domain-included command.

  2. MA5600T(V800R006C02): No matter whether the user uses the default username or configured username, the domain name must be included in the username for logging in. MA5600T (V800R007 and later versions): The username can be configured by running the terminal user authentication-mode AAA domain-name command. After the configuration, the system will add a domain name for the username automatically when the user logs in to the RADIUS server for authentication.

  3. The display terminal user command is used to query users without domain names.

  4. The user with domain name has limited authority on the Radius server and needs to configure the priority to 2 on the Radius to enter the config mode.

  5. MA5600T of version V800R006C02 does not support it. The V800R007 and later versions of MA5600T can support this configuration for some accounts (excluding the root and admin account): run the terminal user authentication-mode AAA domain-name command to set the authentication mode of the terminal user to AAA. In this case:

    The system can add an .@huawei to the username that has no domain name.

    The AAA account can be used to log in remotely, and the account can pass the authentication. If the local account is used to log in remotely, then the account cannot pass the authentication. However, the root and admin account can pass the authentication for remote login, other local accounts cannot.


Thanks.

View more
  • x
  • convention:

All Answers

Hi, dear friend.


According to the description of your question, the answers are as follows:

  1. Yes, the domain name must be included in the user username for logging in to the device no matter whether the user of RADIUS authentication has configured the username that excludes the domain name by running the undo radius-server user-name domain-included command.

  2. MA5600T(V800R006C02): No matter whether the user uses the default username or configured username, the domain name must be included in the username for logging in. MA5600T (V800R007 and later versions): The username can be configured by running the terminal user authentication-mode AAA domain-name command. After the configuration, the system will add a domain name for the username automatically when the user logs in to the RADIUS server for authentication.

  3. The display terminal user command is used to query users without domain names.

  4. The user with domain name has limited authority on the Radius server and needs to configure the priority to 2 on the Radius to enter the config mode.

  5. MA5600T of version V800R006C02 does not support it. The V800R007 and later versions of MA5600T can support this configuration for some accounts (excluding the root and admin account): run the terminal user authentication-mode AAA domain-name command to set the authentication mode of the terminal user to AAA. In this case:

    The system can add an .@huawei to the username that has no domain name.

    The AAA account can be used to log in remotely, and the account can pass the authentication. If the local account is used to log in remotely, then the account cannot pass the authentication. However, the root and admin account can pass the authentication for remote login, other local accounts cannot.


Thanks.

View more
  • x
  • convention:

Comment

You need to log in to comment to the post Login | Register
Comment

Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " User Agreement."

My Followers

Login and enjoy all the member benefits

Login

Block
Are you sure to block this user?
Users on your blacklist cannot comment on your post,cannot mention you, cannot send you private messages.
Reminder
Please bind your phone number to obtain invitation bonus.