
1.4.5 Checking the Configuration
Prerequisites
The RADIUS AAA configurations are complete.
Procedure
l
Run the
display aaa configuration
command to check the AAA summary.
l
Run the
display authentication-scheme
[
authentication-scheme-name
] command to
check the authentication scheme configuration.
l
Run the
display accounting-scheme
[
accounting-scheme-name
] command to check the
accounting scheme configuration.
l
Run the
display service-scheme
[
name
name
] command to check the service scheme
configuration.
l
Run the
display radius-server configuration
[
template
template-name
] command to
check the RADIUS server template configuration.
l
Run the
display radius-attribute
[
template
template-name
]
disable
command to check
the disabled RADIUS attributes.
l
Run the
display radius-attribute
[
template
template-name
]
translate
command to check
the RADIUS attribute translation configuration.
l
Run the
display domain
[
name
domain-name
] command to check the domain
configuration.
----End
1.5 Configuring HWTACACS AAA
Similar to RADIUS, HWTACACS uses the client/server model to communicate with the
HWTACACS server, implementing authentication, authorization, and accounting (AAA) for
access users. Compared with RADIUS, HWTACACS is more reliable in transmission and
encryption and is therefore more suitable for security control.
1.5.1 Establishing the Configuration Task
Before configuring HWTACACS authentication, authorization, and accounting, familiarize
yourself with the applicable environment, complete the pre-configuration tasks, and obtain the
data required for the configuration. This will help you complete the configuration task quickly
and accurately.
Applicable Environment
To prevent unauthorized users from attacking a network, configure AAA:
l
Authentication: checks whether a user is allowed to access a network. Only authenticated
users can access the network.
l
Authorization: authorizes a user to use specific services.
Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
1 AAA Configuration
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
18