![Huawei Quidway S5600 Скачать руководство пользователя страница 546](http://html.mh-extra.com/html/huawei/quidway-s5600/quidway-s5600_operation-manual_169841546.webp)
Operation Manual – AAA & RADIUS & HWTACACS & EAD
Quidway S5600 Series Ethernet Switches-Release 1510
Chapter 1 AAA & RADIUS & HWTACACS
Configuration
Huawei Technologies Proprietary
1-16
Note:
Huawei's CAMS Server is a service management system used to manage networks
and secure networks and user information. Cooperating with other network devices
(such as switches) in a network, the CAMS Server implements the AAA (authentication,
authorization and accounting) services and rights management.
1.3.4 Configuring an AAA Scheme for an ISP Domain
You can configure an AAA scheme in one of the following two ways:
I. Configuring a bound AAA scheme
You can use the
scheme
command to specify an AAA scheme. If you specify a
RADIUS or HWTACACS scheme, the authentication, authorization and accounting will
be uniformly implemented by the RADIUS server or TACACS server specified in the
RADIUS or HWTACACS scheme. In this way, you cannot specify different schemes for
authentication, authorization and accounting respectively.
Table 1-7
Configure a bound AAA scheme
Operation
Command
Description
Enter system view
system-view
—
Create an ISP domain
or enter the view of an
existing ISP domain
domain
isp-name
Required
Configure an AAA
scheme for the ISP
domain
scheme
{
local
|
none
|
radius-scheme
radius-scheme-name
[
local
] |
hwtacacs-scheme
hwtacacs-scheme-name
[
local
] }
Required
By default, the ISP
domain uses the
local
AAA
scheme.
Configure an RADIUS
scheme for the ISP
domain
radius-scheme
radius-scheme-name
Optional
This command has
the same effect as
the
scheme
radius-scheme
command.