Configuring the
Attributes for Data to be
Sent to TACACS Servers
Configuring the Timers
of TACACS Servers
Table 423 Configure the attributes for data to be sent to TACACS servers
Operation
Enter system view system-view
Create a
HWTACACS
scheme and enter
its view
Set the format of
the user names to
be sent to
TACACS servers
Set the units of
measure for data
flows sent to
TACACS servers
Set the source IP
address used by
the switch to send
HWTACACS
packets
c
CAUTION: Generally, the access users are named in the userid@isp-name format.
Where, isp-name behind the @ character represents the ISP domain name. If the
TACACS server does not accept the user name carrying isp domain name, it is
necessary to remove the domain name from the user names before they are sent
to the TACACS server.
Table 424 Configure the timers of TACACS servers
Operation
Enter system view
Create a
HWTACACS
scheme and enter
its view
Set the response
timeout time of
TACACS servers
Set the wait time for
the primary server
to restore the active
state
Set the real-time
accounting interval
c
CAUTION:
The setting of real-time accounting interval is indispensable to real-time
■
accounting. After an interval value is set, the device transmits the accounting
Command
hwtacacs scheme
hwtacacs-scheme-name
user-name-format { with-domain
| without-domain }
data-flow-format data { byte |
giga-byte | kilo-byte |
mega-byte }
data-flow-format
packet { giga-packet | kilo-packet
| mega-packet | one-packet }
HWTACACS view
nas-ip ip-address
System view
hwtacacs nas-ip ip-address
Command
system-view
hwtacacs scheme
hwtacacs-scheme-name
timer response-timeout
seconds
timer quiet minutes
timer realtime-accounting
minutes
HWTACACS Configuration
Description
-
Required
By default, no HWTACACS scheme
exists.
Optional
By default, the user names sent
from the switch to TACACS servers
carry ISP domain names.
Optional
By default, in a TACACS scheme,
the unit of measure for data is byte
and that for packets is one-packet.
Optional
By default, no source IP address is
specified; the IP address of the
outbound interface is used as the
source IP address.
Description
-
Required
By default, no HWTACACS scheme
exists.
Optional
By default, the response timeout time
is five seconds.
Optional
By default, the primary server waits
five minutes before restoring the
active state.
Optional
By default, the real-time accounting
interval is 12 minutes.
535