HP A5830 Series Configuration Manual page 41

Security switch
Hide thumbs Also See for A5830 Series:
Table of Contents

Advertisement

the number of stop-accounting attempts reaches the configured limit. In the latter case, the switch
discards the packet.
An HWTACACS server can function as the primary accounting server of one scheme and as the
secondary accounting server of another scheme at the same time.
The IP addresses of the primary and secondary accounting servers cannot be the same. Otherwise, the
configuration fails.
You can remove an accounting server only when no active TCP connection for sending accounting
packets is using it.
HWTACACS does not support accounting for FTP users.
To specify HWTACACS accounting servers and set relevant parameters for an HWTACACS scheme:
To do...
1.
Enter system view.
2.
Enter HWTACACS scheme
view.
3.
Specify the primary
HWTACACS accounting
server.
4.
Specify the secondary
HWTACACS accounting
server.
5.
Enable buffering of stop-
accounting requests to which
no responses are received.
6.
Set the maximum number of
stop-accounting attempts.
Setting the shared keys for HWTACACS packets
The HWTACACS client and HWTACACS server use the MD5 algorithm to encrypt packets exchanged
between them and use shared keys to authenticate the packets. They must use the same shared key for
the same type of packets.
A shared key configured on the switch must be the same as that configured on the HWTACACS server.
To set the shared keys for authenticating HWTACACS packets:
To do...
1.
Enter system view.
2.
Enter HWTACACS scheme
view.
3.
Set the shared keys for
authenticating HWTACACS
authentication, authorization,
and accounting packets.
Use the command...
system-view
hwtacacs scheme hwtacacs-
scheme-name
primary accounting ip-address [
port-number ]
secondary accounting ip-address [
port-number ]
stop-accounting-buffer enable
retry stop-accounting retry-times
Use the command...
system-view
hwtacacs scheme hwtacacs-scheme-
name
key { accounting | authentication |
authorization } [ cipher | simple ] key
33
Remarks
Required.
Configure at least one command.
No accounting server is specified
by default.
Optional.
Enabled by default
Optional.
100 by default.
Remarks
Required
No shared key by default

Advertisement

Table of Contents
loading

Table of Contents