HP 5500 HI Series Configuration Manual page 48

Security
Hide thumbs Also See for 5500 HI Series:
Table of Contents

Advertisement

Specifying the HWTACACS authentication servers
For versions earlier than Release 5206, you can specify one primary authentication server and one
secondary authentication server for an HWTACACS scheme. When the primary server is not available,
the secondary server is used.
For Release 5206 and later versions, you can specify one primary authentication server and up to 16
secondary authentication servers for an HWTACACS scheme. When the primary server is not available,
the device tries to communicate with the secondary servers in the order they are configured. Once a
secondary server in active state is found, the device immediately uses it for HWTACACS authentication.
If redundancy is not required, specify only the primary server.
Follow these guidelines when you specify HWTACACS authentication servers:
An HWTACACS server can function as the primary authentication server of one scheme and as the
secondary authentication server of another scheme at the same time.
The IP addresses of the primary and secondary authentication servers cannot be the same.
Otherwise, the configuration fails.
You can remove an authentication server only when no active TCP connection for sending
authentication packets is using it.
To specify HWTACACS authentication servers for an HWTACACS scheme:
Step
1.
Enter system view.
2.
Enter HWTACACS
scheme view.
3.
Specify HWTACACS
authentication servers.
Specifying the HWTACACS authorization servers
For versions earlier than Release 5206, you can specify one primary authorization server and one
secondary authorization server for an HWTACACS scheme. When the primary server is not available,
the secondary server is used.
For Release 5206 and later versions, you can specify one primary authorization server and up to 16
secondary authorization servers for an HWTACACS scheme. When the primary server is not available,
the device tries to communicate with the secondary servers in the order they are configured. Once a
secondary server in active state is found, the device immediately uses it for HWTACACS authorization.
If redundancy is not required, specify only the primary server.
Follow these guidelines when you specify HWTACACS authorization servers:
Command
system-view
hwtacacs scheme hwtacacs-scheme-name
Specify the primary HWTACACS
authentication server:
primary authentication ip-address
[ port-number | key [ cipher | simple ]
key | vpn-instance
vpn-instance-name ] *
Specify the secondary HWTACACS
authentication server:
secondary authentication ip-address
[ port-number | key [ cipher | simple ]
key | vpn-instance
vpn-instance-name ] *
35
Remarks
N/A
N/A
Configure at least one
command.
No authentication server is
specified by default.
The key [ cipher | simple ] key
option is available in Release
5206 and later versions.

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents