H3C S9500 Series Operation Manual page 1185

Routing switches
Hide thumbs Also See for S9500 Series:
Table of Contents

Advertisement

Operation Manual – AAA RADIUS HWTACACS
H3C S9500 Series Routing Switches
[H3C] hwtacacs scheme hwtac
[H3C-hwtacacs-hwtac] primary authentication 10.110.91.164
[H3C-hwtacacs-hwtac] primary authorization 10.110.91.164
# Configure the authentication, authorization, and accounting keys to expert.
[H3C-hwtacacs-hwtac] key authentication expert
[H3C-hwtacacs-hwtac] key authorization expert
[H3C-hwtacacs-hwtac] key accounting expert
# Configure the system to remove the domain name from a username before it send the
username to the TACACS server.
[H3C-hwtacacs-hwtac] user-name-format without-domain
[H3C-hwtacacs-hwtac] quit
# Associate the domain hwtacacs with the HWTACACS scheme.
[H3C] domain hwtacacs
[H3C-isp-hwtacacs] scheme hwtacacs-scheme hwtac
1.7 Troubleshooting AAA, RADIUS, and HWTACACS
RADIUS/HWTACACS protocol is located on the application layer of TCP/IP protocol
suite. It mainly specifies how to exchange user information between NAS and
RADIUS/HWTACACS server of ISP. So it is very likely to be invalid.
I. Symptom: User authentication/authorization always fails
Solution:
The username may not be in the userid@isp-name format or NAS has not been
configured with a default ISP domain. Please use the username in proper format
and configure the default ISP domain on NAS.
The user may have not been configured in the RADIUS/HWTACACS server
database. Check the database and make sure that the configuration information of
the user does exist in the database.
The user may have input a wrong password. So please make sure that the
supplicant inputs the correct password.
The encryption keys of RADIUS/HWTACACS server and NAS may be different.
Please check carefully and make sure that they are identical.
There
RADIUS/HWTACACS server, which can be discovered through pinging
RADIUS/HWTACACS server from NAS. So please ensure the normal
communication between NAS and RADIUS/HWTACACS server.
might
be
some
1-40
Chapter 1 AAA, RADIUS and HWTACACS
communication
fault
Protocol Configuration
between
NAS
and

Advertisement

Table of Contents
loading

Table of Contents