HP 3600 v2 Series Configuration Manual page 48

Hide thumbs Also See for 3600 v2 Series:
Table of Contents

Advertisement

Creating an HWTACACS scheme
The HWTACACS protocol is configured on a per scheme basis. Before performing other HWTACACS
configurations, follow these steps to create an HWTACACS scheme and enter HWTACACS scheme
view:
Step
1.
Enter system view.
2.
Create an HWTACACS scheme
and enter HWTACACS scheme
view.
NOTE:
Up to 16 HWTACACS schemes can be configured.
A scheme can be deleted only when it is not referenced.
Specifying the HWTACACS authentication servers
You can specify one primary authentication server and up to 16 secondary authentication servers for an
HWTACACS scheme. When the primary server is not available, the switch searches for the secondary
servers in the order they are configured. The first secondary server in active state is used for
communication.
If redundancy is not required, specify only the primary server.
Follow these guidelines when you specify HWTACACS authentication servers:
An HWTACACS server can function as the primary authentication server of one scheme and as a
secondary authentication server of another scheme at the same time.
The IP addresses of the primary and secondary authentication servers cannot be the same.
Otherwise, the configuration fails.
You can remove an authentication server only when no active TCP connection for sending
authentication packets is using it.
To specify HWTACACS authentication servers for an HWTACACS scheme:
Step
1.
Enter system view.
2.
Enter HWTACACS
scheme view.
3.
Specify HWTACACS
authentication servers.
Command
system-view
hwtacacs scheme
hwtacacs-scheme-name
Command
system-view
hwtacacs scheme hwtacacs-scheme-name
Specify the primary HWTACACS
authentication server:
primary authentication ip-address
[ port-number | key [ cipher | simple ]
key | vpn-instance
vpn-instance-name ] *
Specify a secondary HWTACACS
authentication server:
secondary authentication ip-address
[ port-number | key [ cipher | simple ]
key | vpn-instance
vpn-instance-name ] *
35
Remarks
N/A
Not defined by default.
Remarks
N/A
N/A
Configure at least one
command.
No authentication server is
specified by default.

Advertisement

Table of Contents
loading

Table of Contents