
33
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter HWTACACS scheme
view.
hwtacacs scheme
hwtacacs-scheme-name
N/A
3.
Specify a shared key for
secure HWTACACS
authentication, authorization,
or accounting
communication.
key
{
accounting
|
authentication
|
authorization
} {
cipher
|
simple
}
string
By default, no shared key is
specified.
The shared key configured on the
device must be the same as that
configured on the HWTACACS
server.
Specifying a VPN for the scheme
The VPN specified for an HWTACACS scheme applies to all servers in that scheme. If a VPN is also
configured for an individual HWTACACS server, the VPN specified for the HWTACACS scheme does
not take effect on that server.
To specify a VPN for an HWTACACS scheme:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter HWTACACS scheme
view.
hwtacacs scheme
hwtacacs-scheme-name
N/A
3.
Specify a VPN for the
HWTACACS scheme.
vpn-instance
vpn-instance-name
By default, an HWTACACS
scheme belongs to the public
network.
Setting the username format and traffic statistics units
A username is typically in the format
userid
@
isp-name
, where
isp-name
represents the user's ISP domain
name. By default, the ISP domain name is included in a username. However, some HWTACACS servers
do not recognize usernames that contain ISP domain names. In this case, you can configure the device
to remove the domain name from each username to be sent.
If you want two or more ISP domains to reference the same HWTACACS scheme, configure that
HWTACACS scheme to keep the ISP domain name in usernames for domain identification.
The device reports online user traffic statistics in accounting packets. The traffic measurement units are
configurable, but they must be the same as configured on the HWTACACS accounting servers.
To set the username format and traffic statistics units for an HWTACACS scheme:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter HWTACACS scheme
view.
hwtacacs scheme
hwtacacs-scheme-name
N/A
3.
Set the format of usernames
sent to the HWTACACS
servers.
user-name-format
{
keep-original
|
with-domain
|
without-domain
}
By default, the ISP domain name
is included in a username.