Operation Manual – AAA
H3C S5600 Series Ethernet Switches
Chapter 2 AAA Configuration
2-30
2.3.6 Configuring the Attributes of Data to be Sent to TACACS Servers
Follow these steps to configure the attributes for data to be sent to TACACS servers:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Create a HWTACACS
scheme and enter its view
hwtacacs scheme
hwtacacs-scheme-name
Required
By default, no
HWTACACS scheme
exists.
Set the format of the
usernames to be sent to
TACACS server
user-name-format
{
with-domain
|
without-domain
}
Optional
By default, the usernames
sent from the switch to
TACACS server carry ISP
domain names.
data-flow-format data
{
byte
|
giga-byte
|
kilo-byte
|
mega-byte
}
Set the units of data flows
to TACACS servers
data-flow-format packet
{
giga-packet
|
kilo-packet
|
mega-packet
|
one-packet
}
Optional
By default, in a TACACS
scheme, the data unit and
packet unit for outgoing
HWTACACS flows are
byte and one-packet
respectively.
HWTACACS scheme
view
nas-ip ip-address
Set the source IP address
of outgoing HWTACACS
messages
System view
hwtacacs nas-ip
ip-address
Optional
By default, no source IP
address is set; the IP
address of the
corresponding outbound
interface is used as the
source IP address.
Caution:
Generally, the access users are named in the
userid@isp-name
or
userid.isp-name
format. Where,
isp-name
after the “
@
” or “.” character represents the ISP domain name.
If the TACACS server does not accept the usernames that carry ISP domain names, it
is necessary to remove domain names from usernames before they are sent to
TACACS server.
2.3.7 Configuring the Timers Regarding TACACS Servers
Follow these steps to configure the timers regarding TACACS servers: