Operation Manual – AAA-RADIUS-HWTACACS
H3C S3610&S5510 Series Ethernet Switches
Chapter 1 AAA/RADIUS/HWTACACS
Configuration
1-38
Note:
z
If a HWTACACS server does not support a username with the domain name, you
can configure the device to remove the domain name before sending the username
to the server.
z
The
nas-ip
command in HWTACACS scheme view is only for the current
HWTACACS scheme, while the
hwtacacs nas-ip
command in system view is for all
HWTACACS schemes. However, the
nas-ip
command in HWTACACS scheme
view overwrites the configuration of the
hwtacacs nas-ip
command.
1.5.7 Setting Timers Regarding HWTACACS Servers
Follow these steps to set timers regarding TACACS servers:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Create a HWTACACS
scheme and enter
HWTACACS scheme
view
hwtacacs scheme
hwtacacs-scheme-name
Required
Not defined by default
Set the TACACS server
response timeout timer
timer response-timeout
seconds
Optional
5 seconds by default
Set the quiet timer for the
primary server
timer quiet
minutes
Optional
5 minutes by default
Set the real-time
accounting interval
timer
realtime-accounting
minutes
Optional
12 minutes by default
Note:
z
For real-time accounting, a NAS must transmit the accounting information of online
users to the HWTACACS accounting server periodically. Note that if the device
does not receive any response to the information, it does not disconnect the online
users forcibly
z
The real-time accounting interval must be a multiple of 3.
z
The setting of the real-time accounting interval somewhat depends on the
performance of the NAS and the HWTACACS server: a shorter interval requires
higher performance.