
1.
A Telnet user sends a request packet to the AR1200-S.
2.
The AR1200-S sends an authentication request packet to the HWTACACS server after
receiving the request packet.
3.
The HWTACACS server sends an authentication response packet to request the user name.
4.
The AR1200-S sends a packet to request the user name after receiving the authentication
response packet.
5.
The user enters the user name.
6.
The AR1200-S sends an authentication packet containing the user name to the
HWTACACS server.
7.
The HWTACACS server sends an authentication response packet to request the password.
8.
The AR1200-S sends a packet to request the password after receiving the authentication
response packet.
9.
The user enters the password.
10. The AR1200-S sends an authentication packet containing the password to the HWTACACS
server.
11. The HWTACACS server sends an authentication response packet, indicating that the user
has been authenticated.
12. The AR1200-S sends an authorization request packet to the HWTACACS server.
13. The HWTACACS server sends an authorization response packet, indicating that the user
is authorized.
14. The AR1200-S receives the authorization response packet.
15. The AR1200-S sends an Accounting-Start packet to the HWTACACS server.
16. The HWTACACS server sends an accounting response packet and starts accounting.
17. The user starts to access network resources.
18. The user requests to disconnect from the network. The AR1200-S sends an Accounting-
Stop packet to the HWTACACS server.
19. The HWTACACS server sends an Accounting-Stop response packet and stops accounting.
Local Authentication and Authorization
In local authentication and authorization, the user information including the local user name,
password, and attributes is configured on the AR1200-S. Local authentication and authorization
feature fast processing and low operation cost, whereas the amount of information that can be
stored is limited by the hardware capacity of the device.
Local authentication and authorization are often used for administrators. Local authentication
is a backup of RADIUS authentication and HWTACACS authentication. Local authorization is
a backup of HWTACACS authorization.
1.3 Configuring Local Authentication and Authorization
After local authentication and authorization are configured, the AR1200-S authenticates and
authorizes access users based on user information.
Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
1 AAA Configuration
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
5