1-38
z
It is recommended to specify only the primary HWTACACS accounting server if backup is not
required.
z
If both the primary and secondary accounting servers are specified, the secondary one is used
when the primary one is not reachable.
z
The IP addresses of the primary and secondary accounting servers cannot be the same. Otherwise,
the configuration fails.
z
You can remove an accounting server only when no active TCP connection for sending accounting
packets is using it.
z
Currently, HWTACACS does not support keeping accounts on FTP users.
Setting the Shared Key for HWTACACS Packets
When using an HWTACACS server as an AAA server, you can set a key to secure the communications
between the device and the HWTACACS server.
The HWTACACS client and HWTACACS server use the MD5 algorithm to encrypt packets exchanged
between them and a shared key to verify the packets. Only when the same key is used can they
properly receive the packets and make responses.
Follow these steps to set the shared key for HWTACACS packets:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Enter HWTACACS scheme
view
hwtacacs scheme
hwtacacs-scheme-name
—
Set the shared keys for
HWTACACS authentication,
authorization, and accounting
packets
key
{
accounting
|
authentication
|
authorization
}
string
Required
No shared key exists by
default.
Configuring Attributes Related to the Data Sent to HWTACACS Server
Follow these steps to configure the attributes related to the data sent to the HWTACACS server:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Enter HWTACACS scheme view
hwtacacs scheme
hwtacacs-scheme-name
—
Specify the format of the
username to be sent to an
HWTACACS server
user-name-format
{
keep-original
|
with-domain
|
without-domain
}
Optional
By default, the ISP domain
name is included in the
username.
Содержание S7906E - Switch
Страница 82: ...1 4 DeviceA interface tunnel 1 DeviceA Tunnel1 service loopback group 1...
Страница 200: ...1 11 DeviceB display vlan dynamic No dynamic vlans exist...
Страница 494: ...ii Displaying and Maintaining Tunneling Configuration 1 45 Troubleshooting Tunneling Configuration 1 45...
Страница 598: ...ii...
Страница 1757: ...4 9...
Страница 1770: ...6 4...
Страница 2017: ...2 11 Figure 2 3 SFTP client interface...
Страница 2062: ...i Table of Contents 1 URPF Configuration 1 1 URPF Overview 1 1 What is URPF 1 1 How URPF Works 1 1 Configuring URPF 1 2...
Страница 2238: ...1 16 DeviceA cfd linktrace service instance 1 mep 1001 target mep 4002...
Страница 2442: ...2 4 Set the interval for sending Syslog or trap messages to 20 seconds Device mac address information interval 20...