
[Huawei]
aaa
[Huawei-aaa]
authentication-scheme l-h
[Huawei-aaa-authen-l-h]
authentication-mode hwtacacs local
[Huawei-aaa-authen-l-h]
authentication-super hwtacacs super
[Huawei-aaa-authen-l-h]
quit
# Create an authorization scheme
HWTACACS
and set HWTACACS authorization.
[Huawei-aaa]
authorization-scheme hwtacacs
[Huawei-aaa-author-hwtacacs]
authorization-mode hwtacacs
[Huawei-aaa-author-hwtacacs]
quit
# Create an accounting scheme
HWTACACS
and set HWTACACS accounting.
[Huawei-aaa]
accounting-scheme hwtacacs
[Huawei-aaa-accounting-hwtacacs]
accounting-mode hwtacacs
# Set the interval of real-time accounting to 3 minutes.
[Huawei-aaa-accounting-hwtacacs]
accounting realtime 3
[Huawei-aaa-accounting-hwtacacs]
quit
Step 3
Configure a domain
huawei
, and apply the authentication scheme
l-h
, authorization scheme
HWTACACS
, accounting scheme
HWTACACS
, and the HWTACACS server template
ht
to
the domain.
[Huawei-aaa]
domain huawei
[Huawei-aaa-domain-huawei]
authentication-scheme l-h
[Huawei-aaa-domain-huawei]
authorization-scheme hwtacacs
[Huawei-aaa-domain-huawei]
accounting-scheme hwtacacs
[Huawei-aaa-domain-huawei]
hwtacacs-server ht
[Huawei-aaa-domain-huawei]
quit
[Huawei-aaa]
quit
Step 4
Verify the configuration.
Run the
display hwtacacs-server template
command on RouterB. You can see that the
configuration of the HWTACACS server template is correct.
<Huawei>
display hwtacacs-server template ht
---------------------------------------------------------------------------
HWTACACS-server template name : ht
Primary-authentication-server : 129.7.66.66:49:-
Primary-authorization-server : 129.7.66.66:49:-
Primary-accounting-server : 129.7.66.66:49:-
Secondary-authentication-server : 129.7.66.67:49:-
Secondary-authorization-server : 129.7.66.67:49:-
Secondary-accounting-server : 129.7.66.67:49:-
Current-authentication-server : 129.7.66.66:49:-
Current-authorization-server : 129.7.66.66:49:-
Current-accounting-server : 129.7.66.66:49:-
Source-IP-address : 0.0.0.0
Shared-key : ****************
Quiet-interval(min) : 5
Response-timeout-Interval(sec) : 5
Domain-included : Yes
Traffic-unit : B
---------------------------------------------------------------------------
Run the
display domain
command on RouterB. You can see that the domain configuration is
correct.
<Huawei>
display domain name huawei
Domain-name : huawei
Domain-state : Active
Authentication-scheme-name : l-h
Accounting-scheme-name : hwtacacs
Authorization-scheme-name : hwtacacs
Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
1 AAA Configuration
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
33