309
Configuring HWTACACS
HW Terminal Access Controller Access Control System (HWTACACS) is an enhanced security
protocol based on TACACS (RFC 1492). HWTACACS is similar to RADIUS, and it uses a
client/server model for information exchange between the network access server (NAS) and the
HWTACACS server.
HWTACACS typically provides AAA services for PPP, VPDN, and terminal users. In a typical
HWTACACS scenario, terminal users need to log in to the NAS. Working as the HWTACACS client,
the NAS sends users' usernames and passwords to the HWTACACS sever for authentication. After
passing authentication and obtaining authorized rights, a user logs in to the device and performs
operations. The HWTACACS server records the operations that each user performs.
Recommended configuration procedure
Step Remarks
1.
Creating the HWTACACS
scheme system
Required.
Create an HWTACACS scheme named
system
.
By default, no HWTACACS scheme exists.
IMPORTANT:
From the Web interface, only one HWTACACS scheme can be
configured, and the scheme is named
system
.
2.
Configuring HWTACACS
servers for the scheme
Authentication server and authorization server are mandatory and
accounting server is optional.
Specify the primary and the secondary HWTACACS servers.
By default, no servers are specified.
IMPORTANT:
If redundancy is not required, specify only the primary AAA servers.
3.
Configuring HWTACACS
communication parameters
for the scheme
Optional.
This section describes how to configure the parameters that are
necessary for information exchange between the device and
HWTACACS servers.
Creating the HWTACACS scheme system
1.
From the navigation tree, select
Authentication
>
HWTACACS
.
The page for adding an HWTACACS scheme appears, as shown in
.
Figure 328 Adding an HWTACACS scheme
2.
Click
Add
.
The
Add HWTACACS Scheme
page appears, as shown in
.
Summary of Contents for FlexNetwork NJ5000
Page 12: ...x Index 440 ...
Page 39: ...27 Figure 16 Configuration complete ...
Page 67: ...55 Figure 47 Displaying the speed settings of ports ...
Page 78: ...66 Figure 59 Loopback test result ...
Page 158: ...146 Figure 156 Creating a static MAC address entry ...
Page 183: ...171 Figure 171 Configuring MSTP globally on Switch D ...
Page 243: ...231 Figure 237 IPv6 active route table ...