- Community Home
- >
- Networking
- >
- Switching and Routing
- >
- Comware Based
- >
- HP Comware 5 RADIUS Authentication will not allow ...
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Discussions
Discussions
Discussions
Forums
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО10-25-2019 01:21 PM
тАО10-25-2019 01:21 PM
HP Comware 5 RADIUS Authentication will not allow level 3
I am attempting to configure RADIUS authentication for some HP 5500 switches running 5.20. I am able to get the switch to allow login, but when I type "sys" I get "unrecognized command". Super asks for a password, when I enter that password it tells me the privilage level for the user is 3 and goes back to the > prompt.
Switch settings
domain system
authentication login radius-scheme RadiusServer local
authorization login radius-scheme RadiusServer local
accounting login none
radius scheme nps
primary authentication 10.1.4.10
primary accounting 10.1.4.10
key authentication sanadmin
key accounting sanadmin
user-name-format without-domain
domain system
authentication login radius-scheme nps local
authorization login radius-scheme nps local
accounting login radius-scheme nps local
Server settings I have tried are Vendor specific for cisco AV pair with a value of shell:roles=network-admin
I have also tired setting a custome of
Window Vendor-Specific Attribute Information
Enter Vendor code: 2011
Window Configure VSA (RFC Compliant)
Vendor-assigned attribute number: 29
Attribute format: Decimal
Attribute value: 3
What can I do to get logged in as level 3?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО11-06-2019 01:20 AM
тАО11-06-2019 01:20 AM
Re: HP Comware 5 RADIUS Authentication will not allow level 3
Hello!
Here is a FreeRADIUS 'users' file config part that should help you to get a better understanding which attributes should be used:
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО11-06-2019 01:31 AM
тАО11-06-2019 01:31 AM
Re: HP Comware 5 RADIUS Authentication will not allow level 3
Regarding your question "Super asks for a password, when I enter that password it tells me the privilage level for the user is 3 and goes back to the > prompt.". Unlike other vendors where '>' prompt is a sign of a limited access and '#' is so called 'privilege exec mode', Comware has totally different ideology where you have two modes - user-view and system-view. User-view is for certaind commads like 'display', 'reset...' etc and in general is for observation only. System-view is for configuration. Logging in with the user name whos privilege level is '3' does not bring you to the 'system-view' directly.