obtains the prompt of entering the user name from the daemon. Then, the NAS displays
the message to the user. When the remote user enters the user name, the NAS transmits
the user name to the daemon. Then, the NAS obtains the prompt of entering the
password, and displays the message to the user. After the remote user enters the
password, the NAS transmits the password to the daemon.
–
HWTACACS authorization. After being authenticated, the user can be authorized. The
NAS communicates with the daemon of the HWTACACS server, and then returns the
accept or reject response of the authorization.
NOTE
l
The HWTACACS configuration only defines the parameters used for data exchange between the
MA5616 and the HWTACACS server. To make these parameters take effect, you need to use the
HWTACACS server group in a domain.
l
The settings of an HWTACACS server template can be modified regardless of whether the template
is bound to a server or not.
Procedure
Step 1
Configure the AAA authentication scheme.
The authentication scheme specifies how all the users in an ISP domain are authenticated.
The system supports up to 16 authentication schemes. The system has a default authentication
scheme named
default
. It can be modified, but cannot be deleted.
1.
Run the
aaa
command to enter the AAA mode.
2.
Run the
authentication-scheme
command to add an authentication scheme.
3.
Run the
authentication-mode hwtacacs
command to configure the authentication mode
of the authentication scheme. Use the HWTACACS protocol to authenticate users.
4.
Run the
quit
command to return to the AAA mode.
Step 2
Configure the AAA authorization scheme.
The authorization scheme specifies how all the users in an ISP domain are authorized.
1.
In the AAA mode, run the
authorization-scheme
command to add an AAA authorization
scheme.
2.
Run the
authorization-mode hwtacacs
command to configure the authorization mode.
3.
Run the
quit
command to return to the AAA mode.
4.
Run the
quit
command to return to the global config mode.
Step 3
Configure the AAA accounting scheme.
The accounting scheme specifies how all the users in an ISP domain are charged.
The system supports up to 128 accounting schemes. The system has a default accounting scheme
named
default
. It can be modified, but cannot be deleted.
1.
In the AAA mode, run the
accounting-scheme
command to add an AAA accounting
scheme.
2.
Run the
accounting-mode hwtacacs
command to configure the accounting mode. By
default, the accounting is not performed.
3.
Run the
accounting interim interval
command to set the interval of real-time accounting.
By default, the interval is 0 minutes, that is, the real-time accounting is not performed.
SmartAX MA5616 Multi-service Access Module
Configuration Guide
3 Basic Configuration
Issue 04 (2011-10-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
101