
31
To do…
Use the command…
Remarks
Enter one or more VTY user
interface views
user-interface vty
first
-
number
[
last-number
]
—
Specify the scheme authentication
mode
authentication-mode
scheme
Required
By default, authentication mode for VTY user
interfaces is
scheme
.
Enable the current user interface to
support either Telnet, SSH, or both
of them
protocol inbound
{
all
|
ssh
}
Optional
By default, both protocols are supported.
Enable command authorization
command authorization
Optional
•
By default, command authorization is not
enabled.
Enable command accounting
command accounting
Optional
•
By default, command accounting is
disabled. The accounting server does not
record the commands executed by users.
•
Command accounting allows the
HWTACACS server to record all executed
commands that are supported by the
device, regardless of the command
execution result. This helps control and
monitor user operations on the device. If
command accounting is enabled and
command authorization is not enabled,
every executed command is recorded on
the HWTACACS server. If both command
accounting and command authorization
are enabled, only the authorized and
executed commands are recorded on the
HWTACACS server.
Exit to system view
quit
—
Enter the default
ISP domain
view
domain
domain-name
Apply the
specified AAA
scheme to the
domain
authentication default
{
hwtacacs-scheme
hwtacacs-scheme-name
[
local
] |
local
|
none
|
radius-scheme
radius-scheme-name
[
local
] }
Configure the
authentication
mode
Exit to system
view
quit
Optional
By default, the AAA scheme is
local
.
Create a local user and enter local
user view
local-user
user-name
Required
By default, no local user exists.
Set the local password
password
{
cipher
|
simple
}
password
Required
By default, no local password is set.