Service Requirements
l
Prefer the HWTACACS server to authenticate management user of domain
isp1
.
l
Local authentication can be used when the HWTACACS server is unreachable.
l
The user logs in to the server carrying the domain name.
l
The HWTACACS server with the IP address 129.7.66.66 functions as the primary server
for authentication.
l
The HWTACACS server with the IP address 129.7.66.67 functions as the secondary server
for authentication.
l
The authentication port ID is 1812.
l
Other parameters adopt the default settings.
Networking
shows the example network of HWTACACS authentication.
Figure 3-32
Example network of HWTACACS authentication
HWTACACS server
(Master)
129.7.66.66
MA5600T
HWTACACS server
(Backup)
129.7.66.67
user1@isp1
user2@isp2
user3@isp3
Telnet
MA5616
Procedure
Step 1
Configure the authentication scheme.
Configure authentication scheme named
login-auth
(users are authenticated through
HWTACACS protocol).
huawei(config)#
aaa
huawei(config-aaa)#
authentication-scheme login-auth
huawei(config-aaa-authen-login-auth)#
authentication-mode hwtacacs
huawei(config-aaa-authen-login-auth)#
quit
Step 2
Configure the HWTACACS protocol.
SmartAX MA5616 Multi-service Access Module
Configuration Guide
3 Basic Configuration
Issue 04 (2011-10-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
108