5-4
Command Accounting Configuration Example
Network diagram
As shown in
Figure 5-3
, configure the commands that the login users execute to be recorded on the
HWTACACS server to control and monitor user operations.
Figure 5-3
Network diagram for configuring command accounting
Internet
Console Connection
Intranet
Host B
192.168.1.20/24
Host A
Host C
10.10.10.10/24
Device
HWTACAS server
192.168.2.20/24
Configuration procedure
# Enable the telnet service on Device.
<Device> system-view
[Device] telnet server enable
# Enable command accounting for users logging in through the console port.
[Device] user-interface aux 0
[Device-ui-aux0] command accounting
[Device-ui-aux0] quit
# Enable command accounting for users logging in through telnet or SSH.
[Device] user-interface vty 0 4
[Device-ui-vty0-4] command accounting
[Device-ui-vty0-4] quit
# Create a HWTACACS scheme named
tac
and configure the IP address and TCP port for the primary
authorization server for the scheme. Ensure that the port number be consistent with that on the
HWTACACS server. Set the shared key for authentication packets to
expert
for the scheme. Specify
Device to remove the domain name in the username sent to the HWTACACS server for the scheme.
[Device] hwtacacs scheme tac
[Device-hwtacacs-tac] primary accounting 192.168.2.20 49
[Device-hwtacacs-tac] key accounting expert
[Device-hwtacacs-tac] user-name-format without-domain
Содержание S7906E - Switch
Страница 82: ...1 4 DeviceA interface tunnel 1 DeviceA Tunnel1 service loopback group 1...
Страница 200: ...1 11 DeviceB display vlan dynamic No dynamic vlans exist...
Страница 494: ...ii Displaying and Maintaining Tunneling Configuration 1 45 Troubleshooting Tunneling Configuration 1 45...
Страница 598: ...ii...
Страница 1757: ...4 9...
Страница 1770: ...6 4...
Страница 2017: ...2 11 Figure 2 3 SFTP client interface...
Страница 2062: ...i Table of Contents 1 URPF Configuration 1 1 URPF Overview 1 1 What is URPF 1 1 How URPF Works 1 1 Configuring URPF 1 2...
Страница 2238: ...1 16 DeviceA cfd linktrace service instance 1 mep 1001 target mep 4002...
Страница 2442: ...2 4 Set the interval for sending Syslog or trap messages to 20 seconds Device mac address information interval 20...