256
C
HAPTER
26: AAA
AND
RADIUS/HWTACACS P
ROTOCOL
C
ONFIGURATION
By default, the IP address of local RADIUS authentication server group is 127.0.0.1
and the password is 3Com.
When using local RADIUS server function, note that,
1
The number of UDP port used for authentication/authorization is 1645 and that
for accounting is 1646.
2
The
password
configured by
local-server
command must be the same as that of
the RADIUS authentication/authorization packet configured by the command
key
authentication
in radius scheme view.
3
Switch 8800 Family series serving as local RADIUS authentication servers currently
only support the CHAP and PAP authentication modes; they do not support the
MD5-challenge mode.
Configuring
HWTACACS Protocol
The following sections describe HWTACACS configuration tasks.
■
“Creating a HWTACAS Scheme”
■
“Configuring HWTACACS Authentication Servers”
■
“Configuring HWTACACS Authorization Servers”
■
“Configuring HWTACACS Accounting Servers and the Related Attributes”
■
“Configuring the Source Address for HWTACACS Packets Sent by NAS”
■
“Setting a Key for Securing the Communication with TACACS Server”
■
“Setting the Username Format Acceptable to the TACACS Server”
■
“Setting the Unit of Data Flows Destined for the TACACS Server”
■
“Setting Timers Regarding TACACS Server”
n
Pay attention to the following when configuring a TACACS server:
■
HWTACACS server does not check whether a scheme is being used by users
when changing most of HWTACS attributes, unless you delete the scheme.
■
By default, the TACACS server has no key.
In the above configuration tasks, creating HWTACACS scheme and configuring
TACACS authentication/authorization server are required; all other tasks are
optional and you can determine whether to perform these configurations as
needed.
Creating a HWTACAS
Scheme
As aforementioned, HWTACACS protocol is configured scheme by scheme.
Therefore, you must create a HWTACACS scheme and enter HWTACACS view
before you perform other configuration tasks.
Perform the following configuration in system view.
Table 228
Create/Delete a local RADIUS authentication server
Operation
Command
Create a local RADIUS authentication server
local-server nas-ip
ip
-
address
key
password
Delete a local RADIUS authentication server
undo local-server nas-ip
ip
-
address
Summary of Contents for Switch 8807
Page 14: ......
Page 32: ...32 CHAPTER 2 COMMAND LINE INTERFACE...
Page 50: ...50 CHAPTER 5 MANAGEMENT INTERFACE CONFIGURATION...
Page 54: ...54 CHAPTER 6 CONFIGURATION FILE MANAGEMENT...
Page 64: ...64 CHAPTER 8 SUPER VLAN CONFIGURATION...
Page 70: ...70 CHAPTER 9 ISOLATE USER VLAN CONFIGURATION...
Page 78: ...78 CHAPTER 10 IP ADDRESS CONFIGURATION...
Page 82: ...82 CHAPTER 11 IP PERFORMANCE CONFIGURATION flag ACK window 16079...
Page 100: ...100 CHAPTER 13 ETHERNET PORT CONFIGURATION...
Page 114: ...114 CHAPTER 15 PORT ISOLATION CONFIGURATION...
Page 158: ...158 CHAPTER 18 DIGEST SNOOPING CONFIGURATION...
Page 162: ...162 CHAPTER 19 FAST TRANSITION...
Page 219: ......
Page 220: ...220 CHAPTER 24 VLAN ACL CONFIGURATION...
Page 234: ...234 CHAPTER 25 802 1X CONFIGURATION...
Page 284: ...284 CHAPTER 28 IP ROUTING PROTOCOL OVERVIEW...
Page 290: ...290 CHAPTER 29 STATIC ROUTE CONFIGURATION...
Page 338: ...338 CHAPTER 31 OSPF CONFIGURATION...
Page 392: ...392 CHAPTER 33 BGP CONFIGURATION...
Page 404: ...404 CHAPTER 34 IP ROUTING POLICY CONFIGURATION...
Page 406: ...406 CHAPTER 35 ROUTE CAPACITY CONFIGURATION...
Page 408: ...408 CHAPTER 36 RECURSIVE ROUTING CONFIGURATION...
Page 416: ...416 CHAPTER 37 IP MULTICAST OVERVIEW...
Page 430: ...430 CHAPTER 39 IGMP SNOOPING CONFIGURATION...
Page 454: ...454 CHAPTER 42 IGMP CONFIGURATION...
Page 462: ...462 CHAPTER 43 PIM DM CONFIGURATION...
Page 506: ...506 CHAPTER 46 MBGP MULTICAST EXTENSION CONFIGURATION...
Page 528: ...528 CHAPTER 48 MPLS BASIC CAPABILITY CONFIGURATION...
Page 632: ...632 CHAPTER 51 MPLS VLL...
Page 652: ...652 CHAPTER 52 VPLS CONFIGURATION...
Page 666: ...666 CHAPTER 53 VRRP CONFIGURATION...
Page 680: ...680 CHAPTER 56 ARP TABLE SIZE CONFIGURATION...
Page 718: ...718 CHAPTER 59 NETSTREAM CONFIGURATION...
Page 728: ...728 CHAPTER 61 POE CONFIGURATION...
Page 736: ...736 CHAPTER 63 UDP HELPER CONFIGURATION...
Page 746: ...746 CHAPTER 64 SNMP CONFIGURATION...
Page 792: ...792 CHAPTER 68 FILE SYSTEM MANAGEMENT...
Page 800: ...800 CHAPTER 69 DEVICE MANAGEMENT...
Page 810: ...810 CHAPTER 70 FTP TFTP CONFIGURATION...
Page 840: ...840 CHAPTER 72 SYSTEM MAINTENANCE AND DEBUGGING...
Page 844: ...844 CHAPTER 74 PACKET STATISTICS CONFIGURATION...
Page 846: ...846 CHAPTER 75 ETHERNET PORT LOOPBACK DETECTION...
Page 860: ...860 CHAPTER 76 QINQ CONFIGURATION...
Page 866: ...866 CHAPTER 77 NQA CONFIGURATION...
Page 876: ...876 CHAPTER 78 PASSWORD CONTROL CONFIGURATION...