1-36
To do…
Use the command…
Remarks
Clear HWTACACS statistics
reset hwtacacs statistics
{
accounting
|
all
|
authentication
|
authorization
}
Available in user view
Clear buffered stop-accounting
requests that get no responses
reset stop-accounting-buffer
hwtacacs-scheme
hwtacacs-scheme-name
Available in user view
AAA Configuration Examples
AAA for Telnet Users by a HWTACACS Server
Network requirements
As shown in
, configure the switch to use the HWTACACS server to provide authentication,
authorization, and accounting services to login users.
z
The HWTACACS server is used for authentication, authentication, and accounting. Its IP address
is 10.1.1.1.
z
On the switch, set the shared keys for authentication, authorization, and accounting packets to
expert
. Configure the switch to remove the domain name from a user name before sending the
user name to the HWTACACS server.
z
On the HWTACACS server, set the shared keys for packets exchanged with the switch to
expert
.
Figure 1-7
Configure AAA for Telnet users by a HWTACACS server
Internet
Switch
Telnet user
Authentication/Accounting server
10.1.1.1/24
Configuration procedure
# Configure the IP addresses of the interfaces (omitted).
# Enable the Telnet server on the switch.
<Switch> system-view
[Switch] telnet server enable
# Configure the switch to use AAA for Telnet users.
[Switch] user-interface vty 0 4
[Switch-ui-vty0-4] authentication-mode scheme
[Switch-ui-vty0-4] quit
# Configure the HWTACACS scheme.
Summary of Contents for S5500-SI Series
Page 161: ...3 10 GigabitEthernet1 0 1 2 MANUAL...
Page 220: ...1 7 Clearing ARP entries from the ARP table may cause communication failures...
Page 331: ...1 7 1 1 ms 1 ms 1 ms 1 1 6 1 2 1 ms 1 ms 1 ms 1 1 4 1 3 1 ms 1 ms 1 ms 1 1 2 2 Trace complete...
Page 493: ...2 8...
Page 1111: ...1 10 Installing patches Installation completed and patches will continue to run after reboot...