Operation Manual – AAA-RADIUS-HWTACACS
H3C S3610&S5510 Series Ethernet Switches
Chapter 1 AAA/RADIUS/HWTACACS
Configuration
1-8
Figure 1-4
Segment of a RADIUS packet containing an extended attribute
1.1.4 Introduction to HWTACACS
I. What is HWTACACS
Huawei Terminal Access Controller Access Control System (HWTACACS) is an
enhanced security protocol based on TACACS (RFC 1492). Similar to RADIUS, it uses
the server/client model to implement AAA for the accessing of different types of terminal
users.
Compared with RADIUS, HWTACACS provides more reliable transmission and
encryption, and therefore is more suitable for security control.
Table 1-3
lists the
primary differences between HWTACACS and RADIUS.
Table 1-3
Primary differences between HWTACACS and RADIUS
HWTACACS
RADIUS
Uses TCP, providing more reliable
network transmission
Uses UDP
Encrypts the entire packet except for the
HWTACACS header
Encrypts only the password field in an
authentication packet
Separates authentication from
authorization. Authentication and
authorization can be deployed on
different HWTACACS servers.
Performs authentication and
authorization in combination
Suitable for security control
Suitable for accounting
Supports authorized use of configuration
commands
Does not support authorized use of
configuration commands
In a typical HWTACACS application, a terminal user needs to log onto the device for
operations. Working as the HWTACACS client, the device sends the username and
password to the HWTACACS server for authentication. After passing authentication
and being authorized, the user can log onto the device to perform operations, as shown
in
Figure 1-5
.