Huawei Quidway S9300 Configuration Manual page 50

Terabit routing switch v100r001c03
Table of Contents

Advertisement

1 AAA and User Management Configuration
Configuration Roadmap
The configuration roadmap is as follows:
1.
2.
Data Preparation
To complete the configuration, you need the following data:
l
l
l
l
The configuration of S9300-A is the same as the configuration of S9300-B; therefore, devices
are not differentiated in the following example. Quidway represents to the device.
Procedure
Step 1 Configure an authentication scheme.
# Enter the AAA view.
<Quidway> system-view
[Quidway] aaa
# Configure an authentication scheme named scheme1, with the authentication mode as
RADIUS.
[Quidway-aaa] authentication-scheme scheme1
[Quidway-aaa-authen-scheme1] authentication-mode radius
[Quidway-aaa-authen-scheme1] quit
[Quidway-aaa] quit
Step 2 Configure a RADIUS server template.
# Configure a RADIUS server template named rrr.
[Quidway] radius-server template rrr
# Configure the IP address and port number of the primary RADIUS authentication server.
[Quidway-radius-rrr] radius-server authentication 10.1.1.1 1812
# Configure the IP address and port number of the secondary RADIUS authentication server.
[Quidway-radius-rrr] radius-server authentication 10.1.1.2 1812 secondary
# Set the shared key and number of times for retransmitting packets on the RADIUS server.
[Quidway-radius-rrr] radius-server shared-key hello
[Quidway-radius-rrr] radius-server retransmit 2
[Quidway-radius-rrr] quit
Step 3 Configure a domain named huawei.
# Create a domain.
1-34
Configure an RADIUS server template and an authentication scheme.
Apply the RADIUS server template and authentication scheme to the domain.
Name of the domain that the user belongs to being huawei
IP address and port number of the primary RADIUS authentication server being 10.1.1.1/24
and 1812
IP address and port number of the secondary RADIUS authentication server being
10.1.1.2/24 and 1812
Shared key being hello and number of times for retransmitting packets being 2 on the
RADIUS server
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
Quidway S9300 Terabit Routing Switch
Configuration Guide - Security
Issue 01 (2009-07-28)

Advertisement

Table of Contents
loading

Table of Contents