
HWTACACS Authentication, Authorization, and Accounting
HWTACACS is an extension of TACACS. Similar to RADIUS, HWTACACS uses the client/
server model to communicate with the HWTACACS server, implementing AAA for access
users. Compared with RADIUS, HWTACACS is more reliable in transmission and encryption,
and is more suitable for security control.
shows messages exchanged between a Telnet user, the AR1200-S, and the
HWTACACS server.
Figure 1-3
HWTACACS authentication, authorization, and accounting
Access user
Router
HWTACACS
server
User logs in
Authentication request packet
Authentication response packet
User accesses network
resources
Authentication response packet
User exits
Authentication response packet
Request the user name
Enter the user name
Authentication request packet
Request the password
Enter the password
Authentication request packet
Authorization request packet
Authorization response packet
Accounting request packet
Accounting-stop response
packet
Accounting-stop packet
Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
1 AAA Configuration
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
4