Configuring Source Address For Hwtacacs Packets Sent By Nas; Setting A Key For Securing The Communication With Tacacs Server; Setting The Username Format Acceptable To The Tacacs Server - 3Com 5500-SI Configuration Manual

5500 series
Hide thumbs Also See for 5500-SI:
Table of Contents

Advertisement

618
C
33: HWTACACS C
HAPTER
Configuring Source
Address for HWTACACS
Packets Sent by NAS
Setting a Key for
Securing the
Communication with
TACACS Server
Setting the Username
Format Acceptable to
the TACACS Server
ONFIGURATION
Perform the following configuration in the corresponding view.
Table 676 Configuring source address for HWTACACS packets sent by the NAS
Operation
Configure the source address for HWTACACS packets sent
from the NAS (HWTACACS view).
Delete the configured source address for HWTACACS
packets sent from the NAS (HWTACACS view).
Configure the source address for HWTACACS packets sent
from the NAS (System view).
Cancel the configured source address for HWTACACS
packets sent from the NAS (System view).
The HWTACACS view takes precedence over the system view when configuring the
source address for HWTACACS packets sent from the NAS.
By default, the source address is not specified, and the interface address for packet
sending is used as the source address.
When using a TACACS server as an AAA server, you can set a key to improve the
communication security between the switch and the TACACS server.
Perform the following configuration in HWTACACS view.
Table 677 Setting a key for securing the communication with the HWTACACS server
Operation
Configure a key for securing the communication
with the accounting, authorization or
authentication server
Delete the configuration
No key is configured by default.
Username is usually in the "userid@isp-name" format, with the domain name
following "@".
If a TACACS server does not accept the username with domain name, you can
remove the domain name and resend it to the TACACS server.
Perform the following configuration in HWTACACS view.
Table 678 Setting the username format acceptable to the TACACS server
Operation
Send username with domain name.
Send username without domain name.
By default, each username sent to a TACACS server contains a domain name.
Command
nas-ip ip-address
undo nas-ip
hwtacacs nas-ip ip-address
undo hwtacacs nas-ip
Command
key { accounting | authorization |
authentication } string
undo key { accounting | authorization |
authentication }
Command
user-name-format with-domain
user-name-format without-domain

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

5500-ei5500g-ei

Table of Contents