HP A7500 Series Configuration Manual page 48

Hide thumbs Also See for A7500 Series:
Table of Contents

Advertisement

To do...
Enable Telnet
Enter one or multiple VTY user
interface views
Specify the scheme
authentication mode
Enable command authorization
Enable command accounting
Exit to system view
Configure
Enter the default ISP
the
domain view
authentic
ation
mode
Specify the AAA
scheme to be
applied to the
domain
Use the command...
telnet server enable
user-interface vty
first-number [ last-number ]
authentication-mode
scheme
command authorization
command accounting
quit
domain domain-name
authentication default
{ hwtacacs-scheme
hwtacacs-scheme-name
[ local ] | local | none |
radius-scheme
radius-scheme-name
[ local ] }
41
Remarks
Required
By default, the Telnet service is disabled.
Required
Whether local, RADIUS, or HWTACACS
authentication is adopted depends on the
configured AAA scheme.
By default, local authentication is adopted.
Optional
By default, command authorization is not
enabled.
Create a HWTACACS scheme, and
specify the IP address of the authorization
server and other authorization
parameters. For more information, see
Security Configuration Guide.
Reference the created HWTACACS
scheme in the ISP domain. For more
information, see Security Configuration
Guide.
Optional
By default, command accounting is
disabled. The accounting server does not
record the commands executed by users.
Command accounting allows the
HWTACACS server to record all executed
commands that are supported by the
device, regardless of the command
execution result. This helps control and
monitor user operations on the device. If
command accounting is enabled and
command authorization is not enabled,
every executed command is recorded on
the HWTACACS server. If both command
accounting and command authorization
are enabled, only the authorized and
executed commands are recorded on the
HWTACACS server.
Optional
By default, the AAA scheme is local.
If you specify the local AAA scheme, perform
the configuration concerning local user as
well. If you specify an existing scheme by
providing the radius-scheme-name argument,
perform the following configuration as well:
For RADIUS and HWTACACS

Advertisement

Table of Contents
loading

Table of Contents