![Huawei Quidway S5600 Operation Manual Download Page 539](http://html.mh-extra.com/html/huawei/quidway-s5600/quidway-s5600_operation-manual_169841539.webp)
Operation Manual – AAA & RADIUS & HWTACACS & EAD
Quidway S5600 Series Ethernet Switches-Release 1510
Chapter 1 AAA & RADIUS & HWTACACS
Configuration
Huawei Technologies Proprietary
1-9
TACACS server
129.7.66.66
TACACS server
129.7.66.67
ISDN /PSTN
Dial-up user
HWTACACS client
Terminal user
TACACS server
129.7.66.66
TACACS server
129.7.66.67
ISDN/PSTN
Dial-up user
HWTACACS client
Terminal user
TACACS server
129.7.66.66
TACACS server
129.7.66.67
ISDN /PSTN
Dial-up user
HWTACACS client
Terminal user
TACACS server
129.7.66.66
TACACS server
129.7.66.67
ISDN/PSTN
Dial-up user
HWTACACS client
Terminal user
Figure 1-5
Network diagram for a typical HWTACACS application
II. Basic message exchange procedure in HWTACACS
For example, use HWTACACS to implement authentication, authorization, and
accounting for a telnet user. Figure 1-6 illustrates the basic message exchange
procedure:
User
HWTACACS
Client
HWTACACS
Server
User logs in
Authentication Start Request packet
Authentication response packet,
requesting for the user name
Request User for the user name
User enters the user name
Authentication continuance packet
carrying the user name
Authentication response packet,
requesting for the password
Request User for the password
User enters the password
Authentication continuance packet
carrying the password
Authentication success packet
Authorization request packet
Authorization success packet
User is permitted
Accounting start request packet
Accounting start response packet
User quits
Accounting stop packet
Accounting stop response packet
User
HWTACACS
Client
HWTACACS
Server
User logs in
Authentication Start Request packet
Authentication response packet,
requesting for the user name
Request User for the user name
User enters the user name
Authentication continuance packet
carrying the user name
Authentication response packet,
requesting for the password
Request User for the password
User enters the password
Authentication continuance packet
carrying the password
Authentication success packet
Authorization request packet
Authorization success packet
User is permitted
Accounting start request packet
Accounting start response packet
User quits
Accounting stop packet
Accounting stop response packet
Figure 1-6
The AAA implementation procedure for a telnet user