39
{
Tries to communicate with the next secondary server in active state that has the highest
priority.
•
The search process continues until the device finds an available secondary server or has
checked all secondary servers in active state. If no server is available, the device considers the
authentication, authorization, or accounting attempt a failure.
•
When the quiet timer of a server expires, the status of the server changes back to active. The
device does not check the server again during the authentication, authorization, or accounting
process.
•
When you remove a server in use, communication with the server times out. The device looks
for a server in active state by first checking the primary server, and then checking secondary
servers in the order they are configured.
•
When the primary server and secondary servers are all in blocked state, the device tries to
communicate with the primary server.
•
When one or more servers are in active state, the device tries to communicate with these active
servers only, even if they are unavailable.
•
When an HWTACACS server's status changes automatically, the device changes this server's
status accordingly in all HWTACACS schemes in which this server is specified.
To set HWTACACS timers:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter HWTACACS scheme
view.
hwtacacs scheme
hwtacacs-scheme-name
N/A
3.
Set the HWTACACS server
response timeout timer.
timer response-timeout
seconds
By default, the HWTACACS
server response timeout timer is 5
seconds.
4.
Set the realtime accounting
interval.
timer realtime-accounting
minutes
By default, the realtime
accounting interval is 12 minutes.
A short interval helps improve
accounting precision but requires
many system resources. When
there are 1000 or more users, set
a longer interval.
5.
Set the server quiet timer.
timer quiet
minutes
By default, the server quiet timer
is 5 minutes.
Displaying and maintaining HWTACACS
Execute
display
commands in any view and
reset
commands in user view.
Task Command
Display the configuration or server
statistics of HWTACACS schemes.
display hwtacacs scheme
[
hwtacacs-server-name
[
statistics
]
Clear HWTACACS statistics.
reset hwtacacs statistics
{
accounting
|
all
|
authentication
|
authorization
}