Huawei Quidway S9300 Configuration Manual page 29

Terabit routing switch
Table of Contents

Advertisement

Quidway S9300 Terabit Routing Switch
Configuration Guide - Security
The system view is displayed.
Step 2 Run:
aaa
The AAA view is displayed.
Step 3 Run:
authorization-scheme authorization-scheme-name
An authorization scheme is created and the authorization scheme view is displayed.
By default, an authorization scheme named default exists on the S9300. This scheme can be
modified but cannot be deleted.
Step 4 Run:
authorization-mode { hwtacacs | if-authenticated | local }
authorization-mode none
The authorization mode is set.
By default, the local authorization mode is used.
If multiple authorization modes are used in an authorization scheme, the non-authorization mode
must be used as the last authorization mode.
When using the HWTACACS authorization mode, you must create an HWTACACS server
template and apply the template to the domain that the user belongs to.
Step 5 (Optional) Run:
authorization-cmd privilege-level hwtacacs [ local ]
The command-line-based authorization function is configured for users at a level.
By default, the command-line-based authorization function is not configured for users at levels
0 to 15.
If command-line authorization is enabled, you must create an HWTACACS server template and
apply the template in the view of the domain that the user belongs to.
Step 6 (Optional) Run:
authorization-cmd no-response-policy { online | offline [ max-times max-times-
value ] }
A policy is configured for command-line-based authorization failure.
By default, a policy is used to keep the user online when command-line-based authorization
fails.
The policy for command-line-based authorization failure is used only when the HWTACACS
server fails or the local user is not configured. The policy for command-line-based authorization
failure cannot be triggered in the following situations:
l
Issue 06 (2010–01–08)
NOTE
If multiple authorization modes are used in an authorization scheme, the authentication modes take effect
according to their configuration sequence. The S9300 adopts the next authorization mode only when the
current authorization mode is invalid. The S9300, however, does not adopt any other authorization mode
when users are not authorized in the current authorization mode.
The server works normally but the input command line fails to pass authorization on the
HWTACACS server.
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
1 AAA and User Management Configuration
*
[ none ] or
1-7

Advertisement

Table of Contents
loading

Table of Contents