Aaa Configuration Examples; Aaa For Telnet Users By An Hwtacacs Server - HP 10500 Series Configuration Manual

Security configuration guide
Hide thumbs Also See for 10500 Series:
Table of Contents

Advertisement

AAA configuration examples

AAA for Telnet users by an HWTACACS server

Network requirements
As shown in
authorization, and accounting.
Set the shared keys for secure communication with the HWTACACS server to expert. Configure the
switch to remove the domain name from a username sent to the HWTACACS server.
Figure 10 Network diagram
 
Configuration procedure
1.
Configure the HWTACACS server:
# On the HWTACACS server, set the shared keys for secure communication with the switch to
expert, add an account for the Telnet user, and specify the password. (Details not shown.)
2.
Configure the switch:
# Assign IP addresses to the interfaces. (Details not shown.)
# Enable the Telnet server on the switch.
<Switch> system-view
[Switch] telnet server enable
# Configure the switch to use AAA for Telnet users.
[Switch] user-interface vty 0 15
[Switch-ui-vty0-15] authentication-mode scheme
[Switch-ui-vty0-15] quit
# Create HWTACACS scheme hwtac.
[Switch] hwtacacs scheme hwtac
# Specify the primary authentication server.
[Switch-hwtacacs-hwtac] primary authentication 10.1.1.1 49
# Specify the primary authorization server.
[Switch-hwtacacs-hwtac] primary authorization 10.1.1.1 49
# Specify the primary accounting server.
[Switch-hwtacacs-hwtac] primary accounting 10.1.1.1 49
Figure
10, configure the switch to use the HWTACACS server for Telnet user authentication,
47

Advertisement

Table of Contents
loading

Table of Contents