Command Manual – AAA&RADIUS&HWTACACS
H3C S3610&S5510 Series Ethernet Switches
Chapter 1 AAA & RADIUS & HWTACACS
Configuration Commands
1-75
Description
Use the
secondary authentication
command to configure a secondary HWTACACS
authentication server.
Use the
undo secondary authentication
command to delete the configured
secondary authentication server.
Note that:
z
You are not allowed to assign the same IP address to both primary and secondary
authentication servers; otherwise, unsuccessful operation is prompted.
z
If you repeatedly use this command, the latest configuration overwrites the
previous one.
z
You can remove an authentication server only when it is not being used by any
active TCP connections.
Related command:
display hwtacacs
.
Example
# Configure a secondary authentication server.
<Sysname> system-view
System View: return to User View with Ctrl+Z.
[Sysname] hwtacacs scheme hwt1
[Sysname-hwtacacs-hwt1] secondary authentication 10.163.155.13 49
1.3.16 secondary authorization
Syntax
secondary authorization ip-address
[
port-number
]
undo secondary authorization
View
HWTACACS scheme view
Parameter
ip-address
: IP address of the server, a valid unicast address in dotted decimal format.
By default, the IP address of the secondary authorization server is 0.0.0.0.
port-number
: Port number of the server, in the range of 1 to 65535. By default, it is 49.
Description
Use the
secondary authorization
command to configure a secondary HWTACACS
authorization server.
Use the .
undo secondary authorization
command to delete the configured
secondary authorization server.