41
To do…
Use the command…
Remarks
Enable command authorization
command authorization
Optional
By default, command authorization is not
enabled.
•
Create a HWTACACS scheme, and
specify the IP address of the authorization
server and other authorization
parameters. For more information, see
Security Configuration Guide
.
•
Reference the created HWTACACS
scheme in the ISP domain. For more
information, see
Security Configuration
Guide
.
Enable command accounting
command accounting
Optional
•
By default, command accounting is
disabled. The accounting server does not
record the commands executed by users.
•
Command accounting allows the
HWTACACS server to record all executed
commands that are supported by the
device, regardless of the command
execution result. This helps control and
monitor user operations on the device. If
command accounting is enabled and
command authorization is not enabled,
every executed command is recorded on
the HWTACACS server. If both command
accounting and command authorization
are enabled, only the authorized and
executed commands are recorded on the
HWTACACS server.
Exit to system view
quit
—
Enter the default ISP
domain view
domain
domain-name
Specify the AAA
scheme to be
applied to the
domain
authentication default
{
hwtacacs-scheme
hwtacacs-scheme-name
[
local
] |
local
|
none
|
radius-scheme
radius-scheme-name
[
local
] }
Configure
the
authentic
ation
mode
Exit to system view
quit
Optional
By default, the AAA scheme is
local
.
If you specify the local AAA scheme, perform
the configuration concerning local user as
well. If you specify an existing scheme by
providing the
radius
-
scheme-name
argument,
perform the following configuration as well:
•
For RADIUS and HWTACACS
configuration, see
Security Configuration
Guide
.
•
Configure the username and password on
the AAA server. (For more information, see
Security Configuration Guide
.)
Create a local user and enter
local user view
local-user
user-name
By default, no local user exists.
Set the local password
password
{
cipher
|
simple
}
password
Required
By default, no local password is set.