Huawei AR1200-S Configuration Manual page 47

Enterprise routers
Hide thumbs Also See for AR1200-S:
Table of Contents

Advertisement

Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
[Huawei] aaa
[Huawei-aaa] authentication-scheme l-h
[Huawei-aaa-authen-l-h] authentication-mode hwtacacs local
[Huawei-aaa-authen-l-h] authentication-super hwtacacs super
[Huawei-aaa-authen-l-h] quit
# Create an authorization scheme HWTACACS and set HWTACACS authorization.
[Huawei-aaa] authorization-scheme hwtacacs
[Huawei-aaa-author-hwtacacs] authorization-mode hwtacacs
[Huawei-aaa-author-hwtacacs] quit
# Create an accounting scheme HWTACACS and set HWTACACS accounting.
[Huawei-aaa] accounting-scheme hwtacacs
[Huawei-aaa-accounting-hwtacacs] accounting-mode hwtacacs
# Set the interval of real-time accounting to 3 minutes.
[Huawei-aaa-accounting-hwtacacs] accounting realtime 3
[Huawei-aaa-accounting-hwtacacs] quit
Step 3 Configure a domain huawei, and apply the authentication scheme l-h, authorization scheme
HWTACACS, accounting scheme HWTACACS, and the HWTACACS server template ht to
the domain.
[Huawei-aaa] domain huawei
[Huawei-aaa-domain-huawei] authentication-scheme l-h
[Huawei-aaa-domain-huawei] authorization-scheme hwtacacs
[Huawei-aaa-domain-huawei] accounting-scheme hwtacacs
[Huawei-aaa-domain-huawei] hwtacacs-server ht
[Huawei-aaa-domain-huawei] quit
[Huawei-aaa] quit
Step 4 Verify the configuration.
Run the display hwtacacs-server template command on RouterB. You can see that the
configuration of the HWTACACS server template is correct.
<Huawei> display hwtacacs-server template ht
---------------------------------------------------------------------------
HWTACACS-server template name
Primary-authentication-server
Primary-authorization-server
Primary-accounting-server
Secondary-authentication-server : 129.7.66.67:49:-
Secondary-authorization-server
Secondary-accounting-server
Current-authentication-server
Current-authorization-server
Current-accounting-server
Source-IP-address
Shared-key
Quiet-interval(min)
Response-timeout-Interval(sec)
Domain-included
Traffic-unit
---------------------------------------------------------------------------
Run the display domain command on RouterB. You can see that the domain configuration is
correct.
<Huawei> display domain name huawei
Domain-name
Domain-state
Authentication-scheme-name
Accounting-scheme-name
Authorization-scheme-name
Issue 02 (2012-03-30)
: ht
: 129.7.66.66:49:-
: 129.7.66.66:49:-
: 129.7.66.66:49:-
: 129.7.66.67:49:-
: 129.7.66.67:49:-
: 129.7.66.66:49:-
: 129.7.66.66:49:-
: 129.7.66.66:49:-
: 0.0.0.0
: ****************
: 5
: 5
: Yes
: B
: huawei
: Active
: l-h
: hwtacacs
: hwtacacs
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
1 AAA Configuration
33

Advertisement

Table of Contents
loading

Table of Contents