3-43
To do…
Use the command…
Remarks
Enable command authorization
command authorization
Optional
By default, command authorization
is not enabled.
z
Create a HWTACACS scheme,
and specify the IP address of
the authorization server and
other authorization parameters.
For more information, see
AAA
in the
Security Configuration
Guide
.
z
Reference the created
HWTACACS scheme in the ISP
domain. For more information,
see
AAA
in the
Security
Configuration Guide
.
Enable command accounting
command accounting
Optional
z
By default, command
accounting is disabled. The
accounting server does not
record the commands executed
by users.
z
Command accounting allows
the HWTACACS server to
record all executed commands
that are supported by the
device, regardless of the
command execution result. This
helps control and monitor user
operations on the device. If
command accounting is
enabled and command
authorization is not enabled,
every executed command is
recorded on the HWTACACS
server. If both command
accounting and command
authorization are enabled, only
the authorized and executed
commands are recorded on the
HWTACACS server.
Exit to system view
quit
—
Enter the default ISP
domain view
domain
domain-name
Specify the AAA
scheme to be applied to
the domain
authentication default
{
hwtacacs-scheme
hwtacacs-scheme-name
[
local
]
|
local
|
none
|
radius-scheme
radius-scheme-name
[
local
] }
Configure
the
authentic
ation
mode
Exit to system view
quit
Optional
By default, the AAA scheme is
local
.
If you specify the local AAA
scheme, perform the configuration
concerning local user as well. If you
specify an existing scheme by
providing the
radius
-
scheme-name
argument, perform the following
configuration as well:
z
For RADIUS and HWTACACS
configuration, see
AAA
in the
Security Configuration Guide
.
z
Configure the username and
password accordingly on the
AAA server. (For more
information, see
AAA
in the
Security Configuration Guide
.)
Create a local user and enter local
user view
local-user user-name
By default, no local user exists.
Summary of Contents for SR6600 SPE-FWM
Page 112: ...6 101...