
Operation Manual – AAA RADIUS HWTACACS
H3C S5500-EI Series Ethernet Switches
Table of Contents
i
Table of Contents
Chapter 1 AAA/RADIUS/HWTACACS Configuration ................................................................. 1-1
1.1 AAA/RADIUS/HWTACACS Overview ............................................................................... 1-1
1.1.1 Introduction to AAA ................................................................................................. 1-1
1.1.2 Introduction to RADIUS........................................................................................... 1-3
1.1.3 Introduction to HWTACACS.................................................................................... 1-9
1.1.4 Protocols and Standards....................................................................................... 1-12
1.2 AAA/RADIUS/HWTACACS Configuration Task List ....................................................... 1-12
1.3 Configuring AAA .............................................................................................................. 1-14
1.3.1 Configuration Prerequisites................................................................................... 1-14
1.3.2 Creating an ISP Domain ....................................................................................... 1-14
1.3.3 Configuring ISP Domain Attributes ....................................................................... 1-15
1.3.4 Configuring an AAA Authentication Scheme for an ISP Domain.......................... 1-16
1.3.5 Configuring an AAA Authorization Scheme for an ISP Domain............................ 1-17
1.3.6 Configuring an AAA Accounting Scheme for an ISP Domain............................... 1-19
1.3.7 Configuring Local User Attributes ......................................................................... 1-21
1.3.8 Tearing down User Connections Forcibly ............................................................. 1-23
1.4 Configuring RADIUS ........................................................................................................ 1-24
1.4.1 Creating a RADIUS Scheme................................................................................. 1-24
1.4.2 Specifying the RADIUS Authentication/Authorization Servers ............................. 1-24
1.4.3 Configuring the RADIUS Accounting Servers and Relevant Parameters............. 1-25
1.4.4 Setting the Shared Key for RADIUS Packets ....................................................... 1-27
1.4.5 Setting the Maximum Number of RADIUS Request Retransmission Attempts ............ 1-27
1.4.6 Setting the Supported RADIUS Server Type ........................................................ 1-28
1.4.7 Setting the Status of RADIUS Servers.................................................................. 1-28
1.4.8 Configuring Attributes Related to the Data Sent to the RADIUS Server............... 1-29
1.4.9 Setting Timers Regarding RADIUS Servers ......................................................... 1-31
1.4.10 Configuring RADIUS Accounting-on ................................................................... 1-32
1.4.11 Configuring an IP Address for the Security Policy Server .................................. 1-33
1.4.12 Enabling the Listening Port of the RADIUS Client .............................................. 1-33
1.5 Configuring HWTACACS................................................................................................. 1-34
1.5.1 Creating a HWTACAS scheme ............................................................................. 1-34
1.5.2 Specifying the HWTACACS Authentication Servers............................................. 1-34
1.5.3 Specifying the HWTACACS Authorization Servers .............................................. 1-35
1.5.4 Specifying the HWTACACS Accounting Servers.................................................. 1-35
1.5.5 Setting the Shared Key for HWTACACS Packets ................................................ 1-36
1.5.6 Configuring Attributes Related to the Data Sent to the TACACS Server.............. 1-37
1.5.7 Setting Timers Regarding HWTACACS Servers .................................................. 1-38
1.6 Displaying and Maintaining AAA/RADIUS/HWTACACS ................................................. 1-39