Huawei AR1200-S Configuration Manual page 46

Enterprise routers
Hide thumbs Also See for AR1200-S:
Table of Contents

Advertisement

Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
Configuration Roadmap
The configuration roadmap is as follows:
1.
2.
3.
Data Preparation
To complete the configuration, you need the following data:
l
l
l
l
l
Procedure
Step 1 Configure an HWTACACS server template.
# Configure an HWTACACS server template ht.
<Huawei> system-view
[Huawei] hwtacacs-server template ht
# Configure IP addresses and port numbers of the primary HWTACACS authentication,
authorization, and accounting servers.
[Huawei-hwtacacs-ht] hwtacacs-server authentication 129.7.66.66 49
[Huawei-hwtacacs-ht] hwtacacs-server authorization 129.7.66.66 49
[Huawei-hwtacacs-ht] hwtacacs-server accounting 129.7.66.66 49
# Configure the IP addresses and port numbers of the secondary HWTACACS authentication,
authorization, and accounting servers.
[Huawei-hwtacacs-ht] hwtacacs-server authentication 129.7.66.67 49 secondary
[Huawei-hwtacacs-ht] hwtacacs-server authorization 129.7.66.67 49 secondary
[Huawei-hwtacacs-ht] hwtacacs-server accounting 129.7.66.67 49 secondary
# Configure the shared key of the HWTACACS server.
[Huawei-hwtacacs-ht] hwtacacs-server shared-key cipher hello
[Huawei-hwtacacs-ht] quit
Step 2 Configure the authentication scheme, authorization scheme, and accounting scheme.
# Create an authentication scheme 1-h. In the authentication scheme, the system performs
HWTACACS authentication first, and performs local authentication if HWTACACS
authentication fails. HWTACACS authentication is used first if the level of users is upgraded.
Issue 02 (2012-03-30)
Configure an HWTACACS server template.
Configure authentication, authorization, and accounting schemes.
Apply the HWTACACS server template, authentication, authorization, and accounting
schemes to the domain.
Name of the domain that users belong to
Name of the HWTACACS server template
Names of the authentication scheme, authorization scheme, and accounting scheme, and
authentication, authorization, and accounting modes
IP addresses, authentication port numbers, authorization port numbers, and accounting port
numbers of the primary and secondary HWTACACS servers
Shared key of the HWTACACS server
NOTE
The following configurations are performed on RouterB.
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
1 AAA Configuration
32

Advertisement

Table of Contents
loading

Table of Contents