Operation Manual – AAA RADIUS HWTACACS
H3C S5500-EI Series Ethernet Switches
Chapter 1 AAA/RADIUS/HWTACACS
Configuration
1-9
z
Vendor-ID (four bytes): Indicates the ID of the vendor. Its most significant byte is 0
and the other three bytes contain a code complying with RFC 1700. The vendor ID
of H3C is 2011.
z
Vendor-Type: Indicates the type of the sub-attribute.
z
Vendor-Length: Indicates the length of the sub-attribute.
z
Vendor-Data: Indicates the contents of the sub-attribute.
Figure 1-5
Segment of a RADIUS packet containing an extended attribute
1.1.3 Introduction to HWTACACS
Huawei Terminal Access Controller Access Control System (HWTACACS) is an
enhanced security protocol based on TACACS (RFC 1492). Similar to RADIUS, it uses
the server/client model for information exchange between NAS and HWTACACS
server.
HWTACACS implements AAA mainly for such users as Point-to-Point Protocol (PPP)
users, Virtual Private Dial-up Network (VPDN) users, and terminal users. In a typical
HWTACACS application, a terminal user needs to log onto the device for operations.
Working as the HWTACACS client, the device sends the username and password to
the HWTACACS sever for authentication. After passing authentication and being
authorized, the user can log into the device to perform operations.
I. Differences between HWTACACS and RADIUS
HWTACACS and RADIUS have many common features, like implementing AAA, using
a client/server model, using shared keys for user information security and having good
flexibility and extensibility. Meanwhile, they also have differences, as listed in
Table 1-3
.
Table 1-3
Primary differences between HWTACACS and RADIUS
HWTACACS
RADIUS
Uses TCP, providing more reliable
network transmission
Uses UDP, providing higher transport
efficiency
Encrypts the entire packet except for the
HWTACACS header
Encrypts only the password field in an
authentication packet