Figure 3-30
Example network of the AAA application
MA5600T
RADIUS server
HWTACACS server
PC
MA5616
The preceding figure shows that the AAA function can be implemented on the MA5616 in the
following three ways:
l
The MA5616 functions as a local AAA server. In this case, the local AAA needs to be
configured. The local AAA does not support accounting.
l
The MA5616 functions as the client of a remote AAA server, and is connected to the
HWTACACS server through the HWTACACS protocol, thus implementing the AAA.
l
The MA5616 functions as the client of a remote AAA server, and is connected to the
RADIUS server through the RADIUS protocol, thus implementing the AAA. The RADIUS
protocol, however, does not support authorization.
lists the differences between HWTACACS and RADIUS.
Table 3-17
Differences between HWTACACS and RADIUS
HWTACACS
RADIUS
Uses TCP to realize more reliable network
transmission.
Uses UDP for transmission.
Encrypts the body of HWTACACS packets,
except their header.
Encrypts only the password field of the
authenticated packets.
Separated authorization and authentication. Concurrent processing of authentication and
authorization.
Applicable to security control.
Applicable to accounting.
Supports authorization of the configuration
commands on the router.
Does not support the authorization of the
configuration commands on the router.
3.12.1 Configuring the Local AAA
This topic describes how to configure the local AAA so that the user authentication can be
performed locally.
SmartAX MA5616 Multi-service Access Module
Configuration Guide
3 Basic Configuration
Issue 04 (2011-10-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
95