ZXA10 C300 Configuration Manual (CLI)
l
In-band NM mode (The ZXA10 C300 is connected to the server through
the in-band NM channel.)
ZXAN(config)#tacacs-server host 1.2.2.3
l
Out-of-band NM mode (The ZXA10 C300 is connected to the server
through the out-of-band NM channel.)
ZXAN(config)#tacacs-server host vrf mng 1.2.2.3
6.
Configure server group.
l
In-band NM mode
ZXAN(config)#aaa group-server zte
ZXAN(config-sg)#server 1.2.2.3
ZXAN(config-sg)#exit
l
Out-band NM mode
ZXAN(config)#aaa group-server zte
ZXAN(config-sg)#server vrf mng 1.2.2.3
ZXAN(config-sg)#exit
7.
Configure the authorization, authentication, and accounting group.
ZXAN(config)#aaa authentication login default group zte
ZXAN(config)#aaa authorization exec default group zte
ZXAN(config)#aaa accounting commands 10 default stop-only group zte
– End of Steps –
15.3 Configuring RADIUS
RADIUS ensures data safety of the ZXA10 C300 by implementing safety authentication
and authorization for remote users who access the ZXA10 C300.
Context
RADIUS supports two login modes:
l
Telnet
l
SSH
Steps
1.
Configure telnet user authentication type.
ZXAN(config)#user-authentication-type aaa
2.
Configure telnet user authorization type.
ZXAN(config)#user-authorization-type aaa
3.
Configure SSH server authentication mode.
ZXAN(config)#ssh server authentication mode aaa
4.
Configure the RADIUS server group.
15-4
SJ-20130520164529-007|2013-06-30 (R1.0)
ZTE Proprietary and Confidential