Operation Manual – AAA
H3C S3100 Series Ethernet Switches
Chapter 2 AAA Configuration
2-27
Operation
Command
Remarks
Set the IP address and
port number of the
primary TACACS
authorization server
primary authorization
ip-address
[
port
]
Required
By default, the IP address
of the primary
authorization server is
0.0.0.0, and the port
number is 0.
Set the IP address and
port number of the
secondary TACACS
authorization server
secondary authorization
ip-address
[
port
]
Optional
By default, the IP address
of the secondary
authorization server is
0.0.0.0, and the port
number is 0.
Caution:
z
You are not allowed to configure the same IP address for both primary and
secondary authorization servers. If you do this, the system will prompt that the
configuration fails.
z
You can remove a server only when it is not used by any active TCP connection for
sending authorization messages.
2.3.4 Configuring TACACS Accounting Servers
Table 2-27
Configure TACACS accounting servers
Operation
Command
Remarks
Enter system view
system-view
—
Create a HWTACACS
scheme and enter its view
hwtacacs scheme
hwtacacs-scheme-name
Required
By default, no
HWTACACS scheme
exists.
Set the IP address and
port number of the
primary TACACS
accounting server
primary accounting
ip-address
[
port
]
Required
By default, the IP address
of the primary accounting
server is 0.0.0.0, and the
port number is 0.
Set the IP address and
port number of the
secondary TACACS
accounting server
secondary accounting
ip-address
[
port
]
Required
By default, the IP address
of the secondary
accounting server is
0.0.0.0, and the port
number is 0.