32
NOTE:
If both the primary and secondary authentication servers are specified, the secondary one is used when the
primary one is not reachable.
If redundancy is not required, specify only the primary HWTACACS authentication server.
The IP addresses of the primary and secondary authentication servers cannot be the same. Otherwise, the
configuration fails.
You can remove an authentication server only when no active TCP connection for sending authentication packets
is using it.
Specifying the HWTACACS authorization servers
Follow these steps to specify the HWTACACS authorization servers:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Enter HWTACACS scheme
view
hwtacacs scheme
hwtacacs-scheme-
name
—
Specify the primary
HWTACACS authorization
server
primary authorization
ip-address
[
port-
number
]
Required
Configure at least one command.
No authorization server is
specified by default.
Specify the secondary
HWTACACS authorization
server
secondary authorization
ip-address
[
port-number
]
NOTE:
If both the primary and secondary authorization servers are specified, the secondary one is used when the
primary one is not reachable.
If redundancy is not required, specify only the primary HWTACACS authorization server.
The IP addresses of the primary and secondary authorization servers cannot be the same. Otherwise, the
configuration fails.
You can remove an authorization server only when no active TCP connection for sending authorization packets is
using it.
Specifying the HWTACACS accounting servers
Follow these steps to specify the HWTACACS accounting servers and perform related configurations:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Enter HWTACACS scheme
view
hwtacacs scheme
hwtacacs-scheme-
name
—
Specify the primary
HWTACACS accounting server
primary accounting
ip-address
[
port-number
]
Required
Configure at least one command.
No accounting server is specified
by default.
Specify the secondary
HWTACACS accounting server
secondary accounting
ip-address
[
port-number
]