User-Name-Format (Hwtacacs Scheme View) - HP FlexNetwork 7500 Series Command Reference Manual

Hide thumbs Also See for FlexNetwork 7500 Series:
Table of Contents

Advertisement

Usage guidelines
HWTACACS is based on TCP. When the server response timeout timer or the TCP timeout timer
times out, the device is disconnected from the HWTACACS server.
The client timeout period of the associated access module cannot be shorter than the total response
timeout timer of all HWTACACS servers in the scheme. Any violation will result in user logoffs before
the authentication, authorization, or accounting process is complete.
Examples
# In HWTACACS scheme hwt1, set the HWTACACS server response timeout timer to 30 seconds.
<Sysname> system-view
[Sysname] hwtacacs scheme hwt1
[Sysname-hwtacacs-hwt1] timer response-timeout 30
Related commands
display hwtacacs scheme

user-name-format (HWTACACS scheme view)

Use user-name-format to specify the format of the username to be sent to an HWTACACS server.
Use undo user-name-format to restore the default.
Syntax
user-name-format { keep-original | with-domain | without-domain }
undo user-name-format
Default
The ISP domain name is included in the usernames sent to an HWTACACS server.
Views
HWTACACS scheme view
Predefined user roles
network-admin
mdc-admin
Parameters
keep-original: Sends the username to the HWTACACS server as the username is entered.
with-domain: Includes the ISP domain name in the username sent to the HWTACACS server.
without-domain: Excludes the ISP domain name from the username sent to the HWTACACS
server.
Usage guidelines
A username is generally in the userid@isp-name format, of which the isp-name argument is used by
the device to determine the ISP domain to which a user belongs. However, some HWTACACS
servers cannot recognize a username containing an ISP domain name. Before sending a username
including a domain name to such an HWTACACS server, the device must remove the domain name.
This command allows you to specify whether to include a domain name in a username to be sent to
an HWTACACS server.
If an HWTACACS scheme defines that the username is sent without the ISP domain name, do not
apply the scheme to more than one ISP domain. Otherwise, the HWTACACS server will consider two
users in different ISP domains but with the same userid as one user.
140

Advertisement

Table of Contents
loading

Table of Contents