HP 10500 Series Configuration Manual page 47

Security configuration guide
Hide thumbs Also See for 10500 Series:
Table of Contents

Advertisement

2.
The source IP address specified in system view for the VPN or public network, depending on where
the HWTACACS server resides.
3.
The IP address of the outbound interface specified by the route.
To specify a source IP address for all HWTACACS schemes of a VPN or the public network:
Step
1.
Enter system view.
2.
Specify a source IP address
for outgoing HWTACACS
packets.
To specify a source IP address for a specific HWTACACS scheme:
Step
1.
Enter system view.
2.
Enter HWTACACS scheme
view.
3.
Specify a source IP address
for outgoing HWTACACS
packets.
Setting timers for controlling communication with HWTACACS servers
The device uses the following timers to control the communication with an HWTACACS server:
Server response timeout timer (response-timeout)—Defines the HWTACACS request
retransmission interval. After sending an HWTACACS request (authentication, authorization, or
accounting request), the device starts the server response timeout timer. If the device receives no
response from the server before the timer expires, it resends the request.
Primary server quiet timer (quiet)—Defines the duration to keep an unreachable primary server in
blocked state. If a primary server is not reachable, the device changes the server's status to blocked,
starts the primary server quiet timer for the server, and tries to communicate with the secondary
server if the secondary server is configured and in active state. After this timer expires, the device
changes the status of the primary server back to active.
Real-time accounting timer (realtime-accounting)—Defines the interval at which the device sends
real-time accounting updates to the HWTACACS accounting server for online users. To implement
real-time accounting, the device must periodically send real-time accounting packets to the
accounting server for online users.
Consider the performance of the NAS and the HWTACACS server when you set the real-time accounting
interval. A shorter interval requires higher performance.
To set timers for controlling communication with HWTACACS servers:
Step
1.
Enter system view.
2.
Enter HWTACACS scheme
view.
Command
system-view
hwtacacs nas-ip ip-address
[ vpn-instance vpn-instance-name ]
Command
system-view
hwtacacs scheme
hwtacacs-scheme-name
nas-ip ip-address
Command
system-view
hwtacacs scheme
hwtacacs-scheme-name
37
Remarks
N/A
By default, the IP address of the
outbound interface is used as the
source IP address.
Remarks
N/A
N/A
By default, the IP address of the
outbound interface is used as the
source IP address.
Remarks
N/A
N/A

Advertisement

Table of Contents
loading

Table of Contents