62Configure the RADIUS scheme.Create RADIUS scheme rad.[Switch] radius scheme radSpecify the primary authentication server.[Switch-radius-rad] primary authentication 10.1.1.1 1812Specify the primary accounting server.[Switch-radius-rad] primary accounting 10.1.1.1 1813Set the shared key for authentication packets to expert.[Switch-radius-rad] key authentication expertSet the shared key for accounting packets to expert.[Switch-radius-rad] key accounting expertSpecify that a username sent to the RADIUS server carries the domain name.[Switch-radius-rad] user-name-format with-domainSpecify the service type for the RADIUS server, which must be extended when the RADIUS serverruns CAMS or iMC.[Switch-radius-rad] server-type extended[Switch-radius-rad] quitConfigure the AAA methods for the domain.[Switch] domain bbb[Switch-isp-bbb] authentication login radius-scheme rad[Switch-isp-bbb] authorization login radius-scheme rad[Switch-isp-bbb] accounting login radius-scheme rad[Switch-isp-bbb] quitWhen using SSH to log in, a user enters a username in the form userid@bbb for authenticationusing domain bbb.3. Verify the configurationAfter the above configuration, the SSH user should be able to use the configured account toaccess the user interface of the switch. The commands that the user can access depend on thesettings for EXEC users on the CAMS server.Troubleshooting AAATroubleshooting RADIUSSymptom 1: User authentication/authorization always fails.Analysis:1. A communication failure exists between the NAS and the RADIUS server.2. The username is not in the format of userid@isp-name or no default ISP domain is specifiedfor the NAS.3. The user is not configured on the RADIUS server.