1-41
AAA Configuration Examples
AAA for Telnet Users by an HWTACACS Server
Network requirements
As shown in
Figure 1-9
,
z
Configure the switch to use the HWTACACS server to provide authentication, authorization, and
accounting services for Telnet users. The IP address of the server is 10.1.1.1/24.
z
Set the shared keys for authentication, authorization, and accounting packets exchanged with the
HWTACACS server to
expert
. Configure the switch to remove the domain name from a user name
before sending the user name to the HWTACACS server.
Figure 1-9
Configure AAA for Telnet users by an HWTACACS server
Internet
Switch
Telnet user
Authentication/Accounting server
10.1.1.1/24
Configuration procedure
# Configure the IP addresses of the interfaces (omitted).
# Enable the Telnet server on the switch.
<Switch> system-view
[Switch] telnet server enable
# Configure the switch to use AAA for Telnet users.
[Switch] user-interface vty 0 4
[Switch-ui-vty0-4]
authentication-mode scheme
[Switch-ui-vty0-4] quit
# Create HWTACACS scheme
hwtac
.
[Switch] hwtacacs scheme hwtac
# Specify the primary authentication server.
[Switch-hwtacacs-hwtac] primary authentication 10.1.1.1 49
# Specify the primary authorization server.
[Switch-hwtacacs-hwtac] primary authorization 10.1.1.1 49
# Specify the primary accounting server.
[Switch-hwtacacs-hwtac] primary accounting 10.1.1.1 49
# Set the shared key for authentication, authorization, and accounting packets to
expert
.
Содержание S7906E - Switch
Страница 82: ...1 4 DeviceA interface tunnel 1 DeviceA Tunnel1 service loopback group 1...
Страница 200: ...1 11 DeviceB display vlan dynamic No dynamic vlans exist...
Страница 494: ...ii Displaying and Maintaining Tunneling Configuration 1 45 Troubleshooting Tunneling Configuration 1 45...
Страница 598: ...ii...
Страница 1757: ...4 9...
Страница 1770: ...6 4...
Страница 2017: ...2 11 Figure 2 3 SFTP client interface...
Страница 2062: ...i Table of Contents 1 URPF Configuration 1 1 URPF Overview 1 1 What is URPF 1 1 How URPF Works 1 1 Configuring URPF 1 2...
Страница 2238: ...1 16 DeviceA cfd linktrace service instance 1 mep 1001 target mep 4002...
Страница 2442: ...2 4 Set the interval for sending Syslog or trap messages to 20 seconds Device mac address information interval 20...