
Step 9
(Optional) Run:
hwtacacs-server accounting
ip-address
[
port
] [
public-net
|
vpn-instance
vpn-
instance-name
]
secondary
The IP address of the secondary HWTACACS accounting server is specified.
By default, the IP address of the secondary HWTACACS accounting server is 0.0.0.0 and its
port number is 0, and the secondary HWTACACS accounting server is not bound to any VPN
instance.
Step 10
(Optional) Run:
hwtacacs-server source-ip
ip-address
The AR1200-S is configured to encapsulate the source IP address in HWTACACS packets to
be sent to an HWTACACS server.
By default, the source IP address in HWTACACS packets is 0.0.0.0. The AR1200-S uses the
IP address of the actual outbound VLANIF interface as the source IP address in HWTACACS
packets.
After you specify the source IP address in HWTACACS packets, the AR1200-S uses this IP
address to communicate with the HWTACACS server.
Step 11
(Optional) Run:
hwtacacs-server shared-key
[
cipher
|
simple
]
key-string
The shared key is configured.
By default, no shared key is configured.
Step 12
(Optional) Run:
hwtacacs-server user-name domain-included
The AR1200-S is configured to encapsulate the domain name in the user name in HWTACACS
packets to be sent to an HWTACACS server.
By default, the AR1200-S encapsulates the domain name in the user name when sending
HWTACACS packets to an HWTACACS server.
Step 13
(Optional) Run:
hwtacacs-server traffic-unit
{
byte
|
kbyte
|
mbyte
|
gbyte
}
The traffic unit used by an HWTACACS server is configured.
By default, the traffic unit is byte on the AR1200-S.
Step 14
(Optional) Run:
hwtacacs-server timer response-timeout
value
The response timeout interval for an HWTACACS server is set.
By default, the response timeout interval for an HWTACACS server is 5s.
If the AR1200-S does not receive any response from the HWTACACS server within the timeout
interval, it considers that the HWTACACS server is faulty. The the AR1200-S then tries to
perform authentication and authorization by using other methods.
Step 15
(Optional) Run:
hwtacacs-server timer quiet
value
The time for the primary HWTACACS server to return to the active state is set.
Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
1 AAA Configuration
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
24