CLI Reference Guide
298 CHAPTER 7: CONFIGURING AUTHENTICATION, AUTHORIZATION, AND ACCOUNTING PARAMETERS
3 Select one of the following record options:
Select Start-Stop to specify that records are sent at the start of a
session and the end of a session.
Select Stop-Only to specify that records are sent only at the end of a
session.
4 To select the accounting method, click Choose Available, then select
the method from the list:
RADIUS server group — A server group that you have configured
previously.
LOCAL — The WX switch’s local database.
You can add one or both methods to the list.
If you specify a RADIUS server group as the first method and a user is
denied access by the RADIUS server, no accounting is attempted with
the other methods specified in the list.
If you specify LOCAL as the first method and a user is not in the local
user database on the WX, accounting is attempted with a RADIUS
server group if one is defined in the method list.
To add a server group, click Create and go to “To define a RADIUS server
group” on page 268. After you create the server group, click Choose
Available and then select the server group from the list.
5 Click Finish to save changes and close the wizard.
Changing the Order
of Access Rules
Initially, the order of the access rules is based on the order in which you
created them. This determines the order in which the WX matches users
to user globs. The arrangement of access rules is important to avoid
unintentionally denying access to users.
Generally, you want the rules in order of most restrictive to least
restrictive, for example:
sysadmin@example.com
*@it.example.com
*@*.example.com