1-42[Switch-radius-rad] user-name-format with-domain[Switch-radius-rad] quit# Configure the AAA methods for the domain.[Switch] domain bbb[Switch-isp-bbb] authentication login radius-scheme rad[Switch-isp-bbb] authorization login radius-scheme rad[Switch-isp-bbb] accounting login radius-scheme rad[Switch-isp-bbb] quitWhen using SSH to log in, a user enters a username in the form userid@bbb for authentication usingdomain bbb.3) Verify the configurationAfter the above configuration, the SSH user should be able to use the configured account to access theuser interface of the switch. The commands that the user can access depend on the settings for EXECusers on the iMC server.Troubleshooting AAATroubleshooting RADIUSSymptom 1: User authentication/authorization always fails.Analysis:1) A communication failure exists between the NAS and the RADIUS server.2) The username is not in the format of userid@isp-name or no default ISP domain is specified for theNAS.3) The user is not configured on the RADIUS server.4) The password of the user is incorrect.5) The RADIUS server and the NAS are configured with different shared key.Solution:Check that:1) The NAS and the RADIUS server can ping each other.2) The username is in the userid@isp-name format and a default ISP domain is specified on the NAS.3) The user is configured on the RADIUS server.4) The correct password is entered.5) The same shared key is configured on both the RADIUS server and the NAS.Symptom 2: RADIUS packets cannot reach the RADIUS server.Analysis:1) The communication link between the NAS and the RADIUS server is down (at the physical layerand data link layer).2) The NAS is not configured with the IP address of the RADIUS server.3) The UDP ports for authentication/authorization and accounting are not correct.4) The port numbers of the RADIUS server for authentication, authorization and accounting are beingused by other applications.Solution:Check that: