
1.5.2 Configuring AAA Schemes
To use HWTACACS AAA, set the authentication mode in an authentication scheme to
HWTACACS, the authorization mode in an authorization scheme to HWTACACS, and the
accounting mode in an accounting scheme to HWTACACS.
Context
Local authentication or non-authentication can be configured as a backup for HWTACACS
authentication in an authentication scheme. This allows local authentication or non-
authentication to be implemented if HWTACACS authentication fails. When HWTACACS
authorization is used, you can configure local authorization or non-authorization as a backup.
When HWTACACS accounting is used, you can configure non-accounting as a backup.
Procedure
l
Configuring an authentication scheme
1.
Run:
system-view
The system view is displayed.
2.
Run:
aaa
The AAA view is displayed.
3.
Run:
authentication-scheme
authentication-scheme-name
An authentication scheme is created and the authentication scheme view is displayed.
By default, the default authentication scheme is used. The default authentication
scheme can be modified, but it cannot be deleted.
4.
Run:
authentication-mode
hwtacacs
[
none
]
HWTACACS authentication is configured.
By default, local authentication is used.
To configure local authentication as a backup, see
Authentication and Authorization
NOTE
If multiple authentication modes are configured in an authentication scheme, authentication
modes are used according to the sequence in which they were configured. The AR1200-S uses
the authentication mode that was configured later only after the current authentication mode
fails. The AR1200-S stops the authentication if the user fails to pass the authentication.
5.
(Optional) Run:
authentication-super
{
hwtacacs
|
super
}
*
[
none
]
The authentication mode used to upgrade user levels is configured.
6.
(Optional) Run:
quit
Return to the AAA view.
Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
1 AAA Configuration
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
20