
50
Creating an HWTACACS scheme
The HWTACACS protocol is configured on a per scheme basis. Before performing other
HWTACACS configurations, follow these steps to create an HWTACACS scheme and enter
HWTACACS scheme view:
To do…
Use the command…
Remarks
1.
Enter system view
system-view
—
2.
Create an HWTACACS scheme
and enter HWTACACS scheme
view
hwtacacs scheme
hwtacacs-
scheme-name
Required
Not defined by default
•
Up to 16 HWTACACS schemes can be configured.
•
A scheme can be deleted only when it is not referenced.
Specifying the VPN instance
After you specify a VPN instance for an HWTACACS scheme, all the authentication, authorization,
and accounting servers specified for the scheme belong to the VPN instance. However, if you also
specify a VPN instance when specifying a server for the scheme, the server belongs to the specific
VPN instance.
Follow these steps to specify a VPN instance for an HWTACACS scheme:
To do…
Use the command…
Remarks
1.
Enter system view
system-view
—
2.
Enter HWTACACS scheme
view
hwtacacs scheme
hwtacacs-
scheme-name
—
3.
Specify a VPN instance for the
HWTACACS scheme
vpn-instance
vpn-instance-name
Required
Specifying the HWTACACS authentication servers
Follow these steps to specify the HWTACACS authentication servers:
To do…
Use the command…
Remarks
1.
Enter system view
system-view
—
2.
Enter HWTACACS scheme
view
hwtacacs scheme
hwtacacs-
scheme-name
—
3.
Specify the primary
HWTACACS authentication
server
primary authentication
ip-
address
[
port-number
|
vpn-
instance
vpn-instance-name
] *
Required
Configure at least one of the
commands
No authentication server by default
4.
Specify the secondary
HWTACACS authentication
server
secondary authentication
ip-
address
[
port-number
|
vpn-
instance
vpn-instance-name
] *