Configuring Attributes Related To The Data Sent To Hwtacacs Server; Specifying The Source Ip Address For Hwtacacs Packets To Be Sent - H3C S9500E Series Security Configuration Manual

Routing switches
Hide thumbs Also See for S9500E Series:
Table of Contents

Advertisement

Configuring attributes related to the data sent to
HWTACACS server
Follow these steps to configure the attributes related to the data sent to the HWTACACS server:
To do...
1.
Enter system view
2.
Enter HWTACACS scheme view
3.
Specify the format of the username
to be sent to an HWTACACS
server
4.
Specify the unit for data flows or
packets to be sent to an
HWTACACS server
If an HWTACACS server does not support a username with the domain name, you can configure the switch
to remove the domain name before sending the username to the server.
Specifying the source IP address for HWTACACS packets
to be sent
You can specify an IP address as the source address for HWTACACS packets to be sent on a
NAS, so that when the physical outbound interface fails, response packets from the HWTACACS
server can still arrive at the NAS.
You can specify the source IP address for HWTACACS packets to be sent in HWTACACS scheme
view for a specific HWTACACS scheme, or in system view for all HWTACACS schemes whose
servers are in a VPN or the public network.
Before sending an HWTACACS packet, a NAS selects a source IP address in this order:
The source IP address specified for the HWTACACS scheme.
1.
The source IP address specified in system view for the VPN or public network, depending on
2.
where the HWTACACS server resides.
The IP address of the outbound interface.
3.
Follow these steps to specify a source IP address for all HWTACACS schemes in a VPN or the
public network:
To do...
1.
Enter system view
Use the command...
system-view
hwtacacs scheme hwtacacs-
scheme-name
user-name-format { keep-
original | with-domain |
without-domain }
data-flow-format { data {
byte | giga-byte | kilo-
byte | mega-byte } |
packet { giga-packet | kilo-
packet | mega-packet |
one-packet } }*
Use the command...
system-view
53
Remarks
Optional
By default, the ISP domain name
is included in the username.
Optional
The defaults are as follows:
byte for data flows, and
one-packet for data packets.
Remarks

Advertisement

Table of Contents
loading

Table of Contents