3com 4210 PWR 9-Port 3CR17341-91-ME User Manual

Product codes
3CR17341-91-ME
Page of 567
RADIUS Configuration Task List
251
can access after login is determined by the privilege level of the user. For SSH 
users using RSA shared key for authentication, the commands they can access 
are determined by the levels set on their user interfaces.
If the configured authentication method is none or password authentication, 
the command level that a user can access after login is determined by the level 
of the user interface.
If the clients connected to a port have different authorization VLANs, only the 
first client passing the MAC address authentication can be assigned with an 
authorization VLAN. The switch will not assign authorization VLANs for 
subsequent users passing MAC address authentication. In this case, you are 
recommended to connect only one MAC address authentication user or 
multiple users with the same authorization VLAN to a port.
For local RADIUS authentication or local authentication to take effect, the 
VLAN assignment mode must be set to string after you specify authorization 
VLANs for local users.
Cutting Down User 
Connections Forcibly
You can use the display connection command to view the connections of Telnet 
users, but you cannot use the cut connection command to cut down their 
connections.
RADIUS Configuration 
Task List
3Com’s Ethernet switches can function not only as RADIUS clients but also as local 
RADIUS servers.
Table 187   Cut down user connections forcibly
Operation 
Command 
Remarks 
Enter system view 
system-view 
Cut down user connections 
forcibly 
cut connection { all | 
access-type { dot1x | 
mac-authentication
 } | 
domain isp-name | interface 
interface-type 
interface-number
 | ip 
ip-address | mac mac-address 
radius-scheme 
radius-scheme-name | vlan 
vlan-id | ucibindex ucib-index 
user-name user-name } 
Required