35
To do…
Use the command…
Remarks
Enter HWTACACS scheme
view
hwtacacs scheme
hwtacacs-
scheme-name
—
Specify a source IP address
for outgoing HWTACACS
packets
nas-ip
ip-address
Required
By default, the IP address of the outbound
interface is used as the source IP address.
Setting timers for controlling communication with HWTACACS servers
Follow these steps to set timers regarding HWTACACS servers:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Enter HWTACACS scheme view
hwtacacs scheme
hwtacacs-
scheme-name
—
Set the HWTACACS server
response timeout timer
timer response-timeout
seconds
Optional
5 seconds by default
Set the quiet timer for the primary
server
timer quiet
minutes
Optional
5 minutes by default
Set the real-time accounting
interval
timer realtime-accounting
minutes
Optional
12 minutes by default
NOTE:
For real-time accounting, a NAS must transmit the accounting information of online users to the HWTACACS
accounting server periodically. If the device does not receive any response to the information, it does not forcibly
disconnect the online users.
The real-time accounting interval must be a multiple of 3.
The setting of the real-time accounting interval somewhat depends on the performance of the NAS and the
HWTACACS server. A shorter interval requires higher performance.
Displaying and maintaining HWTACACS
To do…
Use the command…
Remarks
Display configuration information or
statistics of HWTACACS schemes
display hwtacacs
[
hwtacacs-server-
name
[
statistics
] ] [
slot
slot-number
] [
|
{
begin
|
exclude
|
include
}
regular-
expression
]
Available in any view
Display information about buffered
stop-accounting requests that get no
responses
display stop-accounting-buffer
hwtacacs-scheme
hwtacacs-scheme-
name
[
slot
slot-number
] [
|
{
begin
|
exclude
|
include
}
regular-expression
]
Available in any view
Clear HWTACACS statistics
reset hwtacacs statistics
{
accounting
|
all
|
authentication
|
authorization
} [
slot
slot-number
]
Available in user view