50
Displaying and maintaining AAA
Task Command
Remarks
Display the configuration
information of ISP domains.
display domain
[
isp-name
] [
|
{
begin
|
exclude
|
include
}
regular-expression
]
Available in any view
Display information about user
connections.
display
connection
[
access-type
{
dot1x
|
mac-authentication
|
portal
} |
domain
isp-name
|
interface
interface-type
interface-number
|
ip
ip-address
|
mac
mac-address
|
ucibindex
ucib-index
|
user-name
user-name
|
vlan
vlan-id
] [
slot
slot-number
] [
|
{
begin
|
exclude
|
include
}
regular-expression
]
Available in any view
AAA configuration examples
Unless otherwise noted, devices in the configuration examples are operating in non-FIPS mode.
AAA for Telnet users by an HWTACACS server
Network requirements
As shown in
, configure the switch to use the HWTACACS server to provide authentication,
authorization, and accounting services for Telnet users.
Set the shared keys for secure communication with the HWTACACS server to
expert
. Configure the
switch to remove the domain name from a username before sending the username to the HWTACACS
server.
Figure 11
Network diagram
Configuration procedure
1.
Configure the switch:
# Assign IP addresses to the interfaces. (Details not shown.)
# Enable the Telnet server on the switch.
<Switch> system-view
[Switch] telnet server enable