3-71
To do…
Use the command…
Remarks
Apply the
specified AAA
scheme to the
domain
authentication default
{
hwtacacs-scheme
hwtacacs-scheme-name
[
local
] |
local
|
none
|
radius-scheme
radius-scheme-name
[
local
] }
ation
mode
Return to
system view
quit
If you specify the local AAA scheme,
perform the configuration
concerning local user as well. If you
specify an existing scheme by
providing the
radius
-
scheme-name
argument, perform the following
configuration as well:
z
For RADIUS and HWTACACS
configuration, see
AAA
in the
Security Configuration Guide
.
z
Configure the username and
password accordingly on the
AAA server. (For more
information, see
AAA
in the
Security Configuration Guide
.)
Create a local user and
enter local user view
local-user user-name
Required
By default, no local user exists.
Set the authentication
password for the local user
password
{
cipher
|
simple
}
password
Required
Specifies the command
level of the local user
authorization-attribute level level
Optional
By default, the command level is 0.
Specify the service type for
the local user
service-type
terminal
Required
By default, no service type is
specified.
Configure common settings
for VTY user interfaces
—
Optional
See
for VTY User Interfaces (Optional)
.
After you enable command authorization, you need to perform the following configuration to make the
function take effect:
z
Create a HWTACACS scheme, and specify the IP address of the authorization server and other
authorization parameters. For more information, see AAA in the Security Configuration Guide.
z
Reference the created HWTACACS scheme in the ISP domain. For more information, see
AAA
in
the
Security Configuration Guide
.
After you enable command accounting, you need to perform the following configuration to make the
function take effect:
z
Create a HWTACACS scheme, and specify the IP address of the accounting server and other
accounting parameters. For more information, see
AAA
in the
Security Configuration Guide
.
z
Reference the created HWTACACS scheme in the ISP domain. For more information, see
AAA
in
the
Security Configuration Guide
.
When users adopt the scheme mode to log in to the device, the level of the commands that the users
can access depends on the user privilege level defined in the AAA scheme.
z
When the AAA scheme is local, the user privilege level is defined by the
authorization-attribute
level level
command.
z
When the AAA scheme is RADIUS or HWTACACS, the user privilege level is configured on the
RADIUS or HWTACACS server.
For more information about AAA, RADIUS, and HWTACACS, see
AAA
in the
Security Configuration
Guide
.
Summary of Contents for SR6600 SPE-FWM
Page 112: ...6 101...