11-Security Configuration Guide

HomeSupportResource CenterRoutersH3C SR6600-X Router SeriesH3C SR6600-X Router SeriesTechnical DocumentsConfigure & DeployConfiguration GuidesH3C SR6602-X Routers Configuration Guides-R7607-6W10011-Security Configuration Guide
Table of Contents
Related Documents
03-User profile configuration
Title Size Download
03-User profile configuration 41.44 KB

Configuring user profiles

Overview

A user profile saves a set of predefined parameters, such as a CAR policy, a QoS policy, or a connection limit policy.

The user profile application allows flexible traffic policing on a per-user basis. Each time a user passes authentication, the device automatically applies the parameters in the user profile to this user.

The user profile restricts authenticated user behavior as follows:

1.     After the authentication server verifies a user, the server sends the device the name of the user profile specified for the user.

2.     The device applies the parameters in the user profile to the user.

3.     When the user logs out, the device automatically removes the user profile parameters.

Configuration restrictions and guidelines

When you configure user profiles, follow these restrictions and guidelines:

·     Configure authentication parameters before you create a user profile. The user profile supports working with PPPoE, portal, and IPoE.

·     Specify a user profile for each user account:

¡     In remote authentication, specify a user profile on the authentication server.

¡     In local authentication, specify a user profile in the local user view. For information about local users, see "Configuring AAA."

Configuring a user profile

Step

Command

Remarks

1.     Enter system view.

system-view

N/A

2.     Create a user profile and enter user profile view.

user-profile profile-name

By default, no user profiles exist.

You can use the command to enter the view of an existing user profile.

3.     (Optional.) Specify a queue for session packets that use the user profile.

qos queue { queue-id | queue-name }

By default, no queue exists for saving session packets for a user profile.

Session packets are scheduled based on the scheduling priority that the specified queue has.

4.     Apply a QoS policy, CAR policy, GTS policy, or connection limit policy.

N/A

For information about QoS policy, CAR, and GTS configuration, see ACL and QoS Configuration Guide.

For information about connection limit configuration, see "Configuring connection limits."

 

Displaying and maintaining user profiles

Execute display commands in any view.

 

Task

Command

Display configuration and online user information for the specified user profile or all user profiles (in standalone mode).

display user-profile [ name profile-name ] [ slot slot-number ]

Display configuration and online user information for the specified user profile or all user profiles (in IRF mode).

display user-profile [ name profile-name ] [ chassis chassis-number slot slot-number ]

 

 

  • Cloud & AI
  • InterConnect
  • Intelligent Computing
  • Security
  • SMB Products
  • Intelligent Terminal Products
  • Product Support Services
  • Technical Service Solutions
All Services
  • Resource Center
  • Policy
  • Online Help
All Support
  • Become a Partner
  • Partner Resources
  • Partner Business Management
All Partners
  • Profile
  • News & Events
  • Online Exhibition Center
  • Contact Us
All About Us
新华三官网