Setting A Key For Securing The Communication With Tacacs Server; Setting The Username Format Acceptable To The Tacacs Server - H3C S9500 Series Operation Manual

Routing switches
Hide thumbs Also See for S9500 Series:
Table of Contents

Advertisement

Operation Manual – Security
H3C S9500 Series Routing Switches
Table 2-35 Configure the source address for HWTACACS packets sent by the NAS
Configure the source address for HWTACACS packets
sent from the NAS (HWTACACS view)
Delete the configured source address for HWTACACS
packets sent from the NAS (HWTACACS view)
Configure the source address for HWTACACS packets
sent from the NAS (System view)
Cancel the configured source address for HWTACACS
packets sent from the NAS (System view)
The HWTACACS view takes precedence over the system view when configuring the
source address for HWTACACS packets sent from the NAS.
By default, the source address is not specified, and the virtual interface of the VLAN
that contains the port to which the server connects for packet sending is used as the
source address.

2.4.6 Setting a Key for Securing the Communication with TACACS Server

When using a TACACS server as an AAA server, you can set a key to improve the
communication security between the switch and the TACACS server.
Perform the following configuration in HWTACACS view.
Table 2-36 Set a key for securing the communication with the HWTACACS server
Configure a key for securing the
communication with the accounting,
authorization or authentication server
Delete the configuration
No key is configured by default.

2.4.7 Setting the Username Format Acceptable to the TACACS Server

Username is usually in the "userid@isp-name" format, with the domain name following
"@".
If a TACACS server does not accept the username with domain name, you can remove
the domain name and resend it to the TACACS server.
Perform the following configuration in HWTACACS view.
Operation
Operation
2-30
Chapter 2 AAA and RADIUS/HWTACACS
Protocol Configuration
nas-ip ip-address
undo nas-ip
hwtacacs
ip-address
undo hwtacacs nas-ip
Command
key { accounting | authorization |
authentication } string
undo key { accounting | authorization
| authentication }
Command
nas-ip

Advertisement

Table of Contents
loading

This manual is also suitable for:

S9505S9508S9512

Table of Contents