
Operation Manual – AAA RADIUS HWTACACS
H3C S5500-EI Series Ethernet Switches
Chapter 1 AAA/RADIUS/HWTACACS
Configuration
1-36
To do…
Use the command…
Remarks
Enter system view
system-view
—
Create a HWTACACS
scheme and enter
HWTACACS scheme
view
hwtacacs scheme
hwtacacs-scheme-name
Required
Not defined by default
Configure the IP address
and port of the primary
HWTACACS accounting
server
primary accounting
ip-address
[
port-number
]
Required
The defaults are as
follows:
0.0.0.0 for the IP address,
and
49 for the TCP port.
Configure the IP address
and port of the secondary
HWTACACS accounting
server
secondary accounting
ip-address
[
port-number
]
Required
The defaults are as
follows:
0.0.0.0 for the IP address,
and
49 for the TCP port.
Enable the device to
buffer stop-accounting
requests getting no
responses
stop-accounting-buffer
enable
Optional
Enabled by default
Set the maximum number
of stop-accounting
request transmission
attempts
retry stop-accounting
retry-times
Optional
100 by default
Note:
z
The IP addresses of the primary and secondary accounting servers cannot be the
same. Otherwise, the configuration fails.
z
You can remove an accounting server only when no active TCP connection for
sending accounting packets is using it.
z
Currently, HWTACACS does not support keeping accounts on FTP users.
1.5.5 Setting the Shared Key for HWTACACS Packets
When using a HWTACACS server as an AAA server, you can set a key to secure the
communications between the device and the HWTACACS server.
The HWTACACS client and HWTACACS server use the MD5 algorithm to encrypt
packets exchanged between them and a shared key to verify the packets. Only when
the same key is used can they properly receive the packets and make responses.