Configuring An Authorization Scheme - Huawei Quidway S9300 Configuration Manual

Terabit routing switch
Table of Contents

Advertisement

1 AAA and User Management Configuration
By default, there is an authentication scheme named default on the S9300. This scheme can be
modified but cannot be deleted.
Step 4 Run:
authentication-mode { hwtacacs | radius | local }
Or
authentication-mode none
The authentication mode is set.
none indicates the non-authentication mode. By default, the local authentication mode is used.
If multiple authentication modes are used in an authentication scheme, the non-authentication
mode must be used as the last authentication mode.
If the authentication mode is set to RADIUS or HWTACACS, you must configure a RADIUS
or an HWTACACS server template and apply the template in the view of the domain that the
user belongs to.
Step 5 Run:
authentication-super { hwtacacs | super }
Or,
authentication-super none
The authentication mode for upgrading user levels is set.
The none parameter indicates that the non-authentication mode is used. That is, user levels are
changed by users. By default, the local authentication mode is used for upgrading user levels.
When the local authentication mode is used for upgrading user levels, you need to run the super
password command in the system view to set the password for upgrading user levels. For details
on the super password command, see the Quidway S9300 Terabit Routing Switch Command
Reference - Basic Configurations.
----End

1.3.3 Configuring an Authorization Scheme

Context
Procedure
Step 1 Run:
system-view
1-6
NOTE
If multiple authentication modes are used in an authentication scheme, the authentication modes take effect
according to their configuration sequence. The S9300 adopts the next authorization mode only when the
current authorization mode is invalid. The S9300, however, does not adopt any other authorization mode
when users are not authorized in the current authorization mode.
NOTE
You can configure command-line-based authorization only when HWTACACS is adopted.
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
Quidway S9300 Terabit Routing Switch
Configuration Guide - Security
*
[ none ]
*
[ none ]
Issue 06 (2010–01–08)

Advertisement

Table of Contents
loading

Table of Contents