2-20z Generally, the access users are named in the userid@isp-name or userid.isp-name format. Here,isp-name after the “@” or “.” character represents the ISP domain name, by which the devicedetermines which ISP domain a user belongs to. However, some old RADIUS servers cannotaccept the user names that carry ISP domain names. In this case, it is necessary to removedomain names from user names before sending the user names to RADIUS server. For this reason,the user-name-format command is designed for you to specify whether or not ISP domain namesare carried in the user names to be sent to RADIUS server.z For a RADIUS scheme, if you have specified to remove ISP domain names from user names, youshould not use this RADIUS scheme in more than one ISP domain. Otherwise, such errors mayoccur: the RADIUS server regards two different users having the same name but belonging todifferent ISP domains as the same user (because the usernames sent to it are the same).z In the default RADIUS scheme "system", ISP domain names are removed from user names bydefault.z The purpose of setting the MAC address format of the Calling-Station-Id (Type 31) field in RADIUSpackets is to improve the switch’s compatibility with different RADIUS servers. This setting isnecessary when the format of Calling-Station-Id field recognizable to RADIUS servers is differentfrom the default MAC address format on the switch. For details about field formats recognizable toRADIUS servers, refer to the corresponding RADIUS server manual.Configuring the Local RADIUS Authentication Server FunctionThe switch provides the local RADIUS server function (including authentication and authorization), alsoknown as the local RADIUS authentication server function, in addition to RADIUS client service, whereseparate authentication/authorization server and the accounting server are used for userauthentication.Table 2-20 Configure the local RADIUS authentication server functionOperation Command RemarksEnter system view system-view —Enable UDP port for localRADIUS authentication server local-server enableOptionalBy default, the UDP port for localRADIUS authentication server isenabled.Configure the parameters ofthe local RADIUS serverlocal-server nas-ipip-address key passwordRequiredBy default, a local RADIUSauthentication server isconfigured with an NAS IPaddress of 127.0.0.1.