Huawei Quidway S9300 Configuration Manual page 54

Terabit routing switch v100r001c03
Table of Contents

Advertisement

1 AAA and User Management Configuration
[Quidway-aaa] authentication-scheme scheme1
# Set an authentication mode for the authentication scheme.
[Quidway-aaa-authen-scheme1] authentication-mode local hwtacacs
[Quidway-aaa-authen-scheme1] quit
Step 2 Configure an authorization scheme.
# Create an authorization scheme named scheme1.
[Quidway-aaa] authorization-scheme scheme1
# Set the authorization mode for the authorization scheme.
[Quidway-aaa-author-scheme1] authorization-mode hwtacacs
[Quidway-aaa-author-scheme1] quit
Step 3 Configure an HWTACACS server template.
# Create an HWTACACS server template named hhh.
[Quidway] hwtacacs-server template hhh
# Configure IP addresses and port numbers of primary HWTACACS authentication and
authorization servers.
[Quidway-hwtacacs-hhh] hwtacacs-server authentication 10.1.1.1 49
[Quidway-hwtacacs-hhh] hwtacacs-server authorization 10.1.1.1 49
# Configure IP addresses and port numbers of secondary HWTACACS authentication and
authorization servers.
[Quidway-hwtacacs-hhh] hwtacacs-server authentication 10.1.1.2 49 secondary
[Quidway-hwtacacs-hhh] hwtacacs-server authorization 10.1.1.2 49 secondary
# Set the shared key of the HWTACACS server.
[Quidway-hwtacacs-hhh] hwtacacs-server shared-key crystal
[Quidway-hwtacacs-hhh] quit
Step 4 Configure a domain.
# Create a domain named huawei.
[Quidway] aaa
[Quidway-aaa] domain huawei
# Configure authentication and authorization schemes for the domain.
[Quidway-aaa-domain-huawei] authentication-scheme scheme1
[Quidway-aaa-domain-huawei] authorization-scheme scheme1
# Configure an HWTACACS server template for the domain.
[Quidway-aaa-domain-huawei] hwtacacs-server hhh
[Quidway-aaa-domain-huawei] quit
[Quidway-aaa] quit
Step 5 Set an authentication mode for Telnet users.
[Quidway] user-interface vty 0 4
[Quidway-ui-vty0-4] authentication-mode aaa
[Quidway-ui-vty0-4] quit
Step 6 Verify the configuration.
Run the display hwtacacs-server template command on the S9300, and you can view the
configuration of the HWTACACS server template.
1-38
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
Quidway S9300 Terabit Routing Switch
Configuration Guide - Security
Issue 01 (2009-07-28)

Advertisement

Table of Contents
loading

Table of Contents