
l
Accounting: records all the operations performed by a user and the service type, start time,
and data traffic.
HWTACACS prevents unauthorized users from attacking a network and provides command
line authorization. Compared with RADIUS, HWTACACS is more suitable for security control.
Pre-configuration Tasks
Before configuring HWTACACS authentication, authorization, and accounting, complete the
following task:
l
Configuring physical attributes for interfaces to ensure that the physical layer status of the
interfaces is Up
Data Preparation
To configure HWTACACS authentication, authorization, and accounting, you need the
following data.
No.
Data
1
Name of an authentication scheme
2
Name of an authorization scheme
3
Name of an accounting scheme
4
Name of an HWTACACS server template
5
IP addresses and port numbers of primary and
secondary HWTACACS authentication
servers
6
IP addresses and port numbers of primary and
secondary HWTACACS authorization
servers
7
(Optional) IP addresses and port numbers of
primary and secondary HWTACACS
accounting servers
8
(Optional) Shared key in HWTACACS
packets
9
(Optional) Response timeout interval of an
HWTACACS server
10
(Optional) Time for the primary
HWTACACS server to return to the active
state
11
(Optional) Retransmission interval of
accounting-stop packets
Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
1 AAA Configuration
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
19