Setting The Shared Key For Hwtacacs Packets; Configuring Attributes Related To The Data Sent To Hwtacacs Server - H3C S5120-EI Series Operation Manual

Hide thumbs Also See for S5120-EI Series:
Table of Contents

Advertisement

Setting the Shared Key for HWTACACS Packets

When using a HWTACACS server as an AAA server, you can set a key to secure the communications
between the device and the HWTACACS server.
The HWTACACS client and HWTACACS server use the MD5 algorithm to encrypt packets exchanged
between them and a shared key to verify the packets. Only when the same key is used can they
properly receive the packets and make responses.
Follow these steps to set the shared key for HWTACACS packets:
To do...
Enter system view
Create a HWTACACS scheme
and enter HWTACACS scheme
view
Set the shared keys for
HWTACACS authentication,
authorization, and accounting
packets

Configuring Attributes Related to the Data Sent to HWTACACS Server

Follow these steps to configure the attributes related to the data sent to the HWTACACS server:
To do...
Enter system view
Create a HWTACACS scheme
and enter HWTACACS scheme
view
Specify the format of the
username to be sent to a
HWTACACS server
Specify the unit for data flows or
packets to be sent to a
HWTACACS server
Set the source
IP address of
the device to
send
HWTACACS
packets
Use the command...
system-view
hwtacacs scheme
hwtacacs-scheme-name
key { accounting |
authentication |
authorization } string
Use the command...
system-view
hwtacacs scheme
hwtacacs-scheme-name
user-name-format
{ keep-original |
with-domain |
without-domain }
data-flow-format { data
{ byte | giga-byte | kilo-byte
| mega-byte } | packet
{ giga-packet | kilo-packet |
mega-packet |
one-packet } }*
In HWTACACS
nas-ip ip-address
scheme view
quit
In system view
hwtacacs nas-ip ip-address
1-33
Remarks
Required
Not defined by default
Required
No shared key exists by
default.
Remarks
Required
Not defined by default
Optional
By default, the ISP domain
name is included in the
username.
Optional
The defaults are as follows:
byte for data flows, and
one-packet for data packets.
Use either command
By default, the outbound port
serves as the source IP
address to send HWTACACS
packets.

Advertisement

Chapters

Table of Contents
loading

Table of Contents