
accounting-mode radius
domain default
domain default_admin
domain huawei
authentication-scheme 1
accounting-scheme 1
radius-server shiva
#
return
1.7.2 Example for Configuring HWTACACS Authentication,
Authorization, and Accounting
Networking Requirements
l
The HWTACACS server will authenticate access users first. If HWTACACS
authentication fails, local authentication is used.
l
HWTACACS authentication is required before the level of access users is upgraded. If
HWTACACS authentication fails, local authentication is performed.
l
HWTACACS authorization is performed.
l
HWTACACS accounting is performed.
l
Real-time accounting is performed every 3 minutes.
l
The IP addresses of primary and secondary HWTACACS servers are 129.7.66.66/24 and
129.7.66.67/24. The port number for authentication, accounting, and authorization is 49.
Figure 1-5
Networking diagram of HWTACACS authentication, authorization, and accounting
Router A
Router B
Destination
network
Domain Huawei
Network
129.7.66.66/24
129.7.66.67/24
Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
1 AAA Configuration
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
31