NOTE
l
To prevent the loss of the accounting packets, the MA5616 supports the re-transmission of the
accounting-stop packets of the HWTACACS server.
l
By default, the re-transmit time of the accounting-stop packets of the HWTACACS server is 100.
8.
(Optional) Run the
(undo)hwtacacs-server user-name domain-included
command to
configure the user name (not) to carry the domain name when transmitted to the
HWTACACS server.
l
By default, the user name of the HWTACACS server carries the domain name.
l
After the
undo hwtacacs-server user-name domain-included
command is executed,
the domain name is deleted from the user name when the client sends authentication
and authorization requests to the HWTACACS server. The domain name in the user
name of the accounting request is, however, reserved. This is to ensure that the users
can be distinguished from each other in the accounting.
9.
Run the
quit
command to return to the global config mode.
Step 5
Create a domain.
A domain is a group of users of the same type.
In the user name format userid@domain-name (for example, [email protected]),
"userid" indicates the user name for authentication and "domain-name" followed by "@"
indicates the domain name.
The common domain name for login cannot exceed 15 characters, and the domain name for
802.1x authentication cannot exceed 20 characters.
1.
Run the
aaa
command to enter the AAA mode.
2.
In the AAA mode, run the
domain
command to create a domain.
Step 6
Use the authentication scheme.
You can use an authentication scheme in a domain only after the authentication scheme is
created.
In the domain mode, run the
authentication-scheme
command to use the authentication scheme.
Step 7
Use the accounting scheme.
You can use an accounting scheme in a domain only after the accounting scheme is created.
In the domain mode, run the
accounting-scheme
command to use the accounting scheme.
Step 8
Use the authorization scheme.
You can use an authorization scheme in a domain only after the authorization scheme is created.
In the domain mode, run the
authorization-mode
command to use the authorization scheme.
Step 9
Use the HWTACACS server template.
You can use an HWTACACS server template in a domain only after the HWTACACS server
template is created.
1.
In the domain mode, run the
radius-server template
command to use the HWTACACS
server template.
2.
Run the
quit
command to return to the AAA mode.
----End
SmartAX MA5616 Multi-service Access Module
Configuration Guide
3 Basic Configuration
Issue 04 (2011-10-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
103