Aaa For Telnet Users By Separate Servers - HP 12500 Series Configuration Manual

Routing
Table of Contents

Advertisement

Configuring the switch
# Assign IP addresses to the interfaces. (Details not shown.)
# Enable the Telnet server on the switch.
<Switch> system-view
[Switch] telnet server enable
# Configure the switch to use AAA for Telnet users.
[Switch] user-interface vty 0 4
[Switch-ui-vty0-4] authentication-mode scheme
[Switch-ui-vty0-4] quit
# Create HWTACACS scheme hwtac.
[Switch] hwtacacs scheme hwtac
# Specify the primary authentication server.
[Switch-hwtacacs-hwtac] primary authentication 10.1.1.1 49
# Specify the primary authorization server.
[Switch-hwtacacs-hwtac] primary authorization 10.1.1.1 49
# Specify the primary accounting server.
[Switch-hwtacacs-hwtac] primary accounting 10.1.1.1 49
# Set the shared keys for authenticating authentication, authorization, and accounting packets to expert.
[Switch-hwtacacs-hwtac] key authentication simple expert
[Switch-hwtacacs-hwtac] key authorization simple expert
[Switch-hwtacacs-hwtac] key accounting simple expert
# Specify the scheme to exclude the domain names from usernames to be sent to the HWTACACS server.
[Switch-hwtacacs-hwtac] user-name-format without-domain
[Switch-hwtacacs-hwtac] quit
# Configure the AAA methods for the domain.
[Switch] domain bbb
[Switch-isp-bbb] authentication login hwtacacs-scheme hwtac
[Switch-isp-bbb] authorization login hwtacacs-scheme hwtac
[Switch-isp-bbb] accounting login hwtacacs-scheme hwtac
[Switch-isp-bbb] quit
Verifying the configuration
Telnet to the switch as a user and enter the correct username and password. You pass authentication and
log in to the switch. Issuing the display connection command on the switch, you can see information
about the user connection.

AAA for Telnet users by separate servers

Network requirements
As shown in
and RADIUS accounting services for Telnet users, and to remove the domain name from a username sent
to the servers.
Set the shared keys for communication with the HWTACACS server and the RADIUS server to expert.
Configure the switch to remove the domain name from a username sent to the HWTACACS server.
Figure 1
1, configure the switch to provide local authentication, HWTACACS authorization,
52

Advertisement

Table of Contents
loading

Table of Contents