33
the number of stop-accounting attempts reaches the configured limit. In the latter case, the switch
discards the packet.
An HWTACACS server can function as the primary accounting server of one scheme and as the
secondary accounting server of another scheme at the same time.
The IP addresses of the primary and secondary accounting servers cannot be the same. Otherwise, the
configuration fails.
You can remove an accounting server only when no active TCP connection for sending accounting
packets is using it.
HWTACACS does not support accounting for FTP users.
To specify HWTACACS accounting servers and set relevant parameters for an HWTACACS scheme:
To do…
Use the command…
Remarks
1.
Enter system view.
system-view
—
2.
Enter HWTACACS scheme
view.
hwtacacs scheme
hwtacacs-
scheme-name
—
3.
Specify the primary
HWTACACS accounting
server.
primary accounting
ip-address
[
port-number
]
Required.
Configure at least one command.
No accounting server is specified
by default.
4.
Specify the secondary
HWTACACS accounting
server.
secondary accounting
ip-address
[
port-number
]
5.
Enable buffering of stop-
accounting requests to which
no responses are received.
stop-accounting-buffer enable
Optional.
Enabled by default
6.
Set the maximum number of
stop-accounting attempts.
retry stop-accounting
retry-times
Optional.
100 by default.
Setting the shared keys for HWTACACS packets
The HWTACACS client and HWTACACS server use the MD5 algorithm to encrypt packets exchanged
between them and use shared keys to authenticate the packets. They must use the same shared key for
the same type of packets.
A shared key configured on the switch must be the same as that configured on the HWTACACS server.
To set the shared keys for authenticating HWTACACS packets:
To do…
Use the command…
Remarks
1.
Enter system view.
system-view
—
2.
Enter HWTACACS scheme
view.
hwtacacs scheme
hwtacacs-scheme-
name
—
3.
Set the shared keys for
authenticating HWTACACS
authentication, authorization,
and accounting packets.
key
{
accounting
|
authentication
|
authorization
} [
cipher
|
simple
]
key
Required
No shared key by default
Содержание A5830 Series
Страница 207: ...199 Figure 62 SFTP client interface ...