22
• FTP, SFTP, and SCP users have the root directory of the NAS set as the working directory, but they
do not have the access permission to the root directory.
• Other login users are assigned the default user role. For more information about the default user
role function, see Fundamentals Configuration Guide.
radius-scheme radius-scheme-name: Specifies a RADIUS scheme by its name, a case-insensitive string of
1 to 32 characters.
Usage guidelines
The RADIUS authorization configuration takes effect only when the authentication method and
authorization method of the ISP domain use the same RADIUS scheme.
You can specify one primary authorization method and multiple backup authorization methods.
When the default authorization method is invalid, the device attempts to use the backup authorization
methods in sequence. For example, the authorization login radius-scheme radius-scheme-name local
none command specifies the default RADIUS authorization method and two backup methods (local
authorization and no authorization). The device performs RADIUS authorization by default and performs
local authorization when the RADIUS server is invalid. The device does not perform authorization when
both of the previous methods are invalid.
Examples
# Configure ISP domain test to use local authorization for login users.
<Sysname> system-view
[Sysname] domain test
[Sysname-isp-test] authorization login local
# Configure ISP domain test to use RADIUS scheme rd for login user authorization and use local
authorization as the backup.
<Sysname> system-view
[Sysname] domain test
[Sysname-isp-test] authorization login radius-scheme rd local
Related commands
• authorization default
• hwtacacs scheme
• local-user
• radius scheme
authorization portal
Use authorization portal to configure the authorization method for portal users.
Use undo authorization portal to restore the default.
Syntax
In non-FIPS mode:
authorization portal { local [ none ] | none | radius-scheme radius-scheme-name [ local ] [ none ] }
undo authorization portal
In FIPS mode:
authorization portal { local | radius-scheme radius-scheme-name [ local ] }