Contents
Configuring AAA ························································································································································· 1
Overview ············································································································································································ 1
RADIUS ······································································································································································ 2
HWTACACS ····························································································································································· 7
AAA for MPLS L3VPNs ········································································································································· 11
Protocols and standards ······································································································································· 11
RADIUS attributes ·················································································································································· 11
Configuring AAA schemes ············································································································································ 15
Configuring local users ········································································································································· 16
Configuring RADIUS schemes ······························································································································ 20
Configuring HWTACACS schemes ····················································································································· 28
Configuration prerequisites ·································································································································· 35
Creating an ISP domain ······································································································································· 35
Displaying and maintaining AAA ································································································································ 39
Network requirements ··········································································································································· 39
Configuration procedure ······································································································································ 40
Verifying the configuration ··································································································································· 41
Network requirements ··········································································································································· 41
Configuration procedure ······································································································································ 42
Verifying the configuration ··································································································································· 43
Network requirements ··········································································································································· 43
Configuration procedure ······································································································································ 43
Verifying the configuration ··································································································································· 46
Troubleshooting RADIUS ··············································································································································· 46
RADIUS authentication failure ······························································································································ 46
RADIUS packet delivery failure ···························································································································· 47
RADIUS accounting error ····································································································································· 47
Troubleshooting HWTACACS ······································································································································ 48
Configuring password control ··································································································································· 49
Overview ········································································································································································· 49
Password setting ···················································································································································· 49
User login control ·················································································································································· 51
Logging ··································································································································································· 51
i