l
The MA5600T/MA5603T/MA5608T functions as the client of a remote AAA server, and
is connected to the HWTACACS server through the HWTACACS protocol, implementing
the AAA.
l
The MA5600T/MA5603T/MA5608T functions as the client of a remote AAA server, and
is connected to the RADIUS server through the RADIUS protocol, implementing the AAA.
The RADIUS protocol, however, does not support authorization.
lists the differences between HWTACACS and RADIUS.
Table 2-2
Differences between HWTACACS and RADIUS
HWTACACS
RADIUS
Uses TCP to ensure more reliable network
transmission.
Uses UDP for transmission.
Encrypts the body of HWTACACS packets,
except their header.
Encrypts only the password field of the
authenticated packets.
Separated authorization and authentication. Concurrent processing of authentication and
authorization.
Applicable to security control.
Applicable to accounting.
Supports authorization of the configuration
commands on the router.
Does not support the authorization of the
configuration commands on the router.
2.4.1 Configuring the Local AAA
This topic describes how to configure the local AAA so that the user authentication can be
performed locally.
Context
l
The local AAA configuration is simple, which does not depend on the external server.
l
The local AAA supports only authentication.
Procedure
Step 1
Configure the AAA authentication scheme.
NOTE
l
The authentication scheme specifies how all the users in an Internet service provider (ISP) domain are
authenticated. The system supports up to 16 authentication schemes.
l
The system has a default authentication scheme named
default
. It can be modified, but cannot be deleted.
1.
Run the
aaa
command to enter the AAA mode.
2.
Run the
authentication-scheme
command to add an authentication scheme.
3.
Run the
authentication-mode local
command to configure the authentication mode of the
authentication scheme.
SmartAX MA5600T/MA5603T/MA5608T Multi-service
Access Module
Commissioning and Configuration Guide
2 Basic Configurations
Issue 01 (2014-04-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
227