309
Configuring HWTACACS
HW Terminal Access Controller Access Control System (HWTACACS) is an enhanced security
protocol based on TACACS (RFC 1492). HWTACACS is similar to RADIUS, and it uses a
client/server model for information exchange between the network access server (NAS) and the
HWTACACS server.
HWTACACS typically provides AAA services for PPP, VPDN, and terminal users. In a typical
HWTACACS scenario, terminal users need to log in to the NAS. Working as the HWTACACS client,
the NAS sends users' usernames and passwords to the HWTACACS sever for authentication. After
passing authentication and obtaining authorized rights, a user logs in to the device and performs
operations. The HWTACACS server records the operations that each user performs.
Recommended configuration procedure
Step Remarks
1.
Creating the HWTACACS
scheme system
Required.
Create an HWTACACS scheme named
system
.
By default, no HWTACACS scheme exists.
IMPORTANT:
From the Web interface, only one HWTACACS scheme can be
configured, and the scheme is named
system
.
2.
Configuring HWTACACS
servers for the scheme
Authentication server and authorization server are mandatory and
accounting server is optional.
Specify the primary and the secondary HWTACACS servers.
By default, no servers are specified.
IMPORTANT:
If redundancy is not required, specify only the primary AAA servers.
3.
Configuring HWTACACS
communication parameters
for the scheme
Optional.
This section describes how to configure the parameters that are
necessary for information exchange between the device and
HWTACACS servers.
Creating the HWTACACS scheme system
1.
From the navigation tree, select
Authentication
>
HWTACACS
.
The page for adding an HWTACACS scheme appears, as shown in
.
Figure 328 Adding an HWTACACS scheme
2.
Click
Add
.
The
Add HWTACACS Scheme
page appears, as shown in
.
Содержание FlexNetwork NJ5000
Страница 12: ...x Index 440 ...
Страница 39: ...27 Figure 16 Configuration complete ...
Страница 67: ...55 Figure 47 Displaying the speed settings of ports ...
Страница 78: ...66 Figure 59 Loopback test result ...
Страница 158: ...146 Figure 156 Creating a static MAC address entry ...
Страница 183: ...171 Figure 171 Configuring MSTP globally on Switch D ...
Страница 243: ...231 Figure 237 IPv6 active route table ...
Страница 293: ...281 Figure 298 Ping operation summary ...