
Operation Manual – AAA-RADIUS-HWTACACS
H3C S3610&S5510 Series Ethernet Switches
Chapter 1 AAA/RADIUS/HWTACACS
Configuration
1-36
To do…
Use the command…
Remarks
Configure the IP address
and port of the secondary
HWTACACS accounting
server
secondary accounting
ip-address
[
port-number
]
Required
The defaults are as
follows:
0.0.0.0 for the IP address,
and
49 for the TCP port.
Enable the device to
buffer stop-accounting
requests getting no
responses
stop-accounting-buffer
enable
Optional
Enabled by default
Set the maximum number
of stop-accounting
request transmission
attempts
retry stop-accounting
retry-times
Optional
100 by default
Note:
z
The IP addresses of the primary and secondary accounting servers cannot be the
same. Otherwise, the configuration fails.
z
You can remove an accounting server only when no active TCP connection for
sending accounting packets is using it.
z
Currently, HWTACACS does not support keeping accounts on FTP users.
1.5.5 Setting the Shared Key for HWTACACS Packets
When using a HWTACACS server as an AAA server, you can set a key to secure the
communications between the device and the HWTACACS server.
The HWTACACS client and HWTACACS server use the MD5 algorithm to encrypt
packets exchanged between them and a shared key to verify the packets. Only when
the same key is used can they properly receive the packets and make responses.
Follow these steps to set the shared key for HWTACACS packets:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Create a HWTACACS
scheme and enter
HWTACACS scheme
view
hwtacacs scheme
hwtacacs-scheme-name
Required
Not defined by default