Configuring Aaa Schemes; Establishing The Configuration Task - Huawei Quidway S9300 Configuration Manual

Terabit routing switch
Table of Contents

Advertisement

1 AAA and User Management Configuration
The authorization attribute in the domain takes effect only when the AAA server does not have
or provide this authorization. In this manner, you can add services flexibly based on the domain
management, regardless of the attributes provided by the AAA server.
RADIUS and HWTACACS Server Templates
When RADIUS or HWTACACS is specified in an authentication or an authorization scheme
for communication between the client and the server, you must configure a RADIUS or an
HWTACACS server template.
l
l

1.3 Configuring AAA Schemes

This section describes how to configure an authentication scheme, an authorization scheme, and
a recording scheme on the S9300.

1.3.1 Establishing the Configuration Task

1.3.2 Configuring an Authentication Scheme
1.3.3 Configuring an Authorization Scheme
1.3.4 Configuring an Accounting Scheme
1.3.5 (Optional) Configuring a Recording Scheme
1.3.6 Checking the Configuration
1.3.1 Establishing the Configuration Task
Applicable Environment
An AAA scheme of the S9300 consists of the authentication scheme, authorization scheme,
accounting scheme, and recording scheme. The S9300 chooses the authentication, authorization,
accounting, and recording modes (local processing, remote processing, or no processing) and
relevant parameters for users according to the AAA scheme.
After an AAA scheme is configured, you can apply this AAA scheme (excluding the recording
scheme) to a domain. The S9300 then uses the scheme to perform authentication, authorization,
and accounting for users in the domain. You can configure different recording schemes for
different transactions in the AAA view.
Pre-configuration Tasks
None
1-4
In a RADIUS server template, you can set the attributes such as the IP addresses, port
number, and key of the authentication server and accounting server.
In an HWTACACS template, you can set the attributes such as the IP addresses, port
number, and key of the authentication server, accounting server, and authorization server.
NOTE
Authentication and authorization are used together in RADIUS; therefore, you cannot use RADIUS alone
to perform authorization.
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
Quidway S9300 Terabit Routing Switch
Configuration Guide - Security
Issue 06 (2010–01–08)

Advertisement

Table of Contents
loading

Table of Contents