774
C
HAPTER
53: AAA/RADIUS/HWTACACS C
ONFIGURATION
Configuring Attributes
Related to the Data Sent
to the TACACS Server
Follow these steps to configure the attributes related to the data sent to the
HWTACACS server:
n
■
If a HWTACACS server does not support a username with the domain name,
you can configure the device to remove the domain name before sending the
username to the server.
■
The
nas-ip
command in HWTACACS scheme view is only for the current
HWTACACS scheme, while the
hwtacacs nas-ip
command in system view is
for all HWTACACS schemes. However, the
nas-ip
command in HWTACACS
scheme view overwrites the configuration of the
hwtacacs nas-ip
command.
Setting Timers
Regarding HWTACACS
Servers
Follow these steps to set timers regarding TACACS servers:
Set the shared keys for
HWTACACS authentication,
authorization, and accounting
packets
key
{
accounting
|
authentication
|
authorization
}
string
Required
No shared key exists by
default.
To do…
Use the command…
Remarks
To do…
Use the command…
Remarks
Enter system view
system-view
-
Create a HWTACACS scheme
and enter HWTACACS scheme
view
hwtacacs scheme
hwtacacs-scheme-name
Required
Not defined by default
Specify the format of the
username to be sent to a
HWTACACS server
user-name-format
{
with-domain
|
without-domain
}
Optional
By default, the ISP domain
name is included in the
username.
Specify the unit for data flows
or packets to be sent to a
HWTACACS server
data-flow-format
{
data
{
byte
|
giga-byte
|
kilo-byte
|
mega-byte
} |
packet
{
giga-packet
|
kilo-packet
|
mega-packet
|
one-packet
} }
*
Optional
The defaults are as follows:
byte
for data flows, and
one-packet
for data packets.
Set the source
IP address of
the device to
send
HWTACACS
packets
In
HWTACACS
scheme view
nas-ip
ip-address
Use either command
By default, the outbound port
serves as the source IP
address to send HWTACACS
packets
In system view
quit
hwtacacs nas-ip
ip-address
To do…
Use the command…
Remarks
Enter system view
system-view
-
Create a HWTACACS scheme
and enter HWTACACS
scheme view
hwtacacs scheme
hwtacacs-scheme-name
Required
Not defined by default
Set the TACACS server
response timeout timer
timer response-timeout
seconds
Optional
5 seconds by default
Set the quiet timer for the
primary server
timer quiet
minutes
Optional
5 minutes by default
Содержание 4800G Series
Страница 26: ...26 CHAPTER NETWORKING APPLICATIONS ...
Страница 30: ...30 CHAPTER 1 LOGGING IN TO AN ETHERNET SWITCH ...
Страница 62: ...62 CHAPTER 3 LOGGING IN THROUGH TELNET ...
Страница 70: ...70 CHAPTER 5 LOGGING IN THROUGH WEB BASED NETWORK MANAGEMENT SYSTEM ...
Страница 72: ...72 CHAPTER 6 LOGGING IN THROUGH NMS ...
Страница 82: ...82 CHAPTER 8 CONTROLLING LOGIN USERS ...
Страница 98: ...98 CHAPTER 9 VLAN CONFIGURATION ...
Страница 108: ...108 CHAPTER 10 VOICE VLAN CONFIGURATION ...
Страница 119: ...GVRP Configuration Examples 119 DeviceB display vlan dynamic No dynamic vlans exist ...
Страница 120: ...120 CHAPTER 11 GVRP CONFIGURATION ...
Страница 160: ...160 CHAPTER 17 PORT ISOLATION CONFIGURATION ...
Страница 172: ...172 CHAPTER 19 LINK AGGREGATION CONFIGURATION ...
Страница 196: ...196 CHAPTER 22 DLDP CONFIGURATION ...
Страница 240: ...240 CHAPTER 23 MSTP CONFIGURATION ...
Страница 272: ...272 CHAPTER 27 RIP CONFIGURATION ...
Страница 364: ...364 CHAPTER 29 IS IS CONFIGURATION ...
Страница 426: ...426 CHAPTER 31 ROUTING POLICY CONFIGURATION ...
Страница 442: ...442 CHAPTER 33 IPV6 RIPNG CONFIGURATION ...
Страница 466: ...466 CHAPTER 35 IPV6 IS IS CONFIGURATION ...
Страница 488: ...488 CHAPTER 36 IPV6 BGP CONFIGURATION ...
Страница 498: ...498 CHAPTER 37 ROUTING POLICY CONFIGURATION ...
Страница 540: ...540 CHAPTER 40 TUNNELING CONFIGURATION ...
Страница 552: ...552 CHAPTER 41 MULTICAST OVERVIEW ...
Страница 604: ...604 CHAPTER 43 MLD SNOOPING CONFIGURATION ...
Страница 628: ...628 CHAPTER 46 IGMP CONFIGURATION ...
Страница 699: ...Troubleshooting MSDP 699 4 Verify that the C BSR address is different from the anycast RP address ...
Страница 700: ...700 CHAPTER 48 MSDP CONFIGURATION ...
Страница 812: ...812 CHAPTER 57 DHCP SERVER CONFIGURATION ...
Страница 822: ...822 CHAPTER 58 DHCP RELAY AGENT CONFIGURATION ...
Страница 834: ...834 CHAPTER 61 BOOTP CLIENT CONFIGURATION ...
Страница 850: ...850 CHAPTER 63 IPV4 ACL CONFIGURATION ...
Страница 856: ...856 CHAPTER 64 IPV6 ACL CONFIGURATION ...
Страница 860: ...860 CHAPTER 65 QOS OVERVIEW ...
Страница 868: ...868 CHAPTER 66 TRAFFIC CLASSIFICATION TP AND LR CONFIGURATION ...
Страница 888: ...888 CHAPTER 69 PRIORITY MAPPING ...
Страница 894: ...894 CHAPTER 71 TRAFFIC MIRRORING CONFIGURATION ...
Страница 904: ...904 CHAPTER 72 PORT MIRRORING CONFIGURATION ...
Страница 930: ...930 CHAPTER 74 UDP HELPER CONFIGURATION ...
Страница 990: ...990 CHAPTER 79 FILE SYSTEM MANAGEMENT CONFIGURATION ...
Страница 1000: ...1000 CHAPTER 80 FTP CONFIGURATION ...
Страница 1020: ...1020 CHAPTER 82 INFORMATION CENTER CONFIGURATION ...
Страница 1038: ...1038 CHAPTER 84 SYSTEM MAINTAINING AND DEBUGGING ...
Страница 1046: ...1046 CHAPTER 85 DEVICE MANAGEMENT ...
Страница 1129: ...SSH Client Configuration Examples 1129 SwitchB ...
Страница 1130: ...1130 CHAPTER 88 SSH CONFIGURATION ...
Страница 1160: ...1160 CHAPTER 90 RRPP CONFIGURATION ...
Страница 1180: ...1180 CHAPTER 91 PORT SECURITY CONFIGURATION ...
Страница 1192: ...1192 CHAPTER 92 LLDP CONFIGURATION ...
Страница 1202: ...1202 CHAPTER 93 POE CONFIGURATION ...
Страница 1218: ...1218 CHAPTER 96 HTTPS CONFIGURATION ...