126
As a best practice, specify a loopback interface address as the source IP address for outgoing
HWTACACS packets to avoid HWTACACS packet loss caused by physical port errors.
If you use both the
nas-ip
command and
hwtacacs nas-ip
command, the following guidelines apply:
•
The setting configured by using the
nas-ip
command in HWTACACS scheme view applies only
to the HWTACACS scheme.
•
The setting configured by using the
hwtacacs nas-ip
command in system view applies to all
HWTACACS schemes.
•
The setting in HWTACACS scheme view takes precedence over the setting in system view.
You can specify only one source IPv4 address and one source IPv6 address for an HWTACACS
scheme.
If you do not specify the
ipv6
keyword for the
undo nas-ip
command, the command deletes the
configured source IPv4 address for outgoing HWTACACS packets.
Examples
# In HWTACACS scheme
hwt1
, specify IP address 10.1.1.1 as the source address for outgoing
HWTACACS packets.
<Sysname> system-view
[Sysname] hwtacacs scheme hwt1
[Sysname-hwtacacs-hwt1] nas-ip 10.1.1.1
Related commands
hwtacacs nas-ip
primary accounting (HWTACACS scheme view)
Use
primary accounting
to specify the primary HWTACACS accounting server.
Use
undo primary accounting
to restore the default.
Syntax
primary accounting
{
host-name
|
ipv4-address
|
ipv6
ipv6-address
} [
port-number
|
key
{
cipher
|
simple
}
string
|
single-connection
|
vpn-instance
vpn-instance-name
] *
undo primary accounting
Default
The primary HWTACACS accounting server is not specified.
Views
HWTACACS scheme view
Predefined user roles
network-admin
mdc-admin
Parameters
host-name
: Specifies the host name of the primary HWTACACS accounting server, a
case-insensitive string of 1 to 253 characters.
ipv4-address
: Specifies an IPv4 address of the primary HWTACACS accounting server.
ipv6
ipv6-address
: Specifies an IPv6 address of the primary HWTACACS accounting server.
port-number
: Specifies the service port number of the primary HWTACACS accounting server. The
value range for the TCP port number is 1 to 65535. The default setting is 49.
Содержание FlexNetwork 7500 Series
Страница 350: ...335 Related commands display port security port security enable ...
Страница 379: ...364 Sysname system view Sysname keychain abc mode absolute Sysname keychain abc tcp kind 252 ...
Страница 519: ...504 Related commands display ssh2 algorithm ssh2 algorithm cipher ssh2 algorithm key exchange ssh2 algorithm mac ...