Specifying The Hwtacacs Accounting Servers; Specifying The Shared Keys For Secure Hwtacacs Communication - H3C SR8800-F Configuration Manual

Comware 7 user access
Hide thumbs Also See for SR8800-F:
Table of Contents

Advertisement

Specifying the HWTACACS accounting servers

You can specify one primary accounting server and a maximum of 16 secondary accounting servers
for an HWTACACS scheme. When the primary server is not available, the device searches for the
secondary servers in the order they are configured. The first secondary server in active state is used
for communication.
If redundancy is not required, specify only the primary server. An HWTACACS server can function as
the primary accounting server of one scheme and as the secondary accounting server of another
scheme at the same time.
HWTACACS does not support accounting for FTP, SFTP, and SCP users.
To specify HWTACACS accounting servers for an HWTACACS scheme:
Step
1.
Enter system view.
2.
Enter HWTACACS
scheme view.
3.
Specify HWTACACS
accounting servers.
Specifying the shared keys for secure HWTACACS
communication
The HWTACACS client and server use the MD5 algorithm and shared keys to generate the
Authenticator value for packet authentication and user password encryption. The client and server
must use the same key for each type of communication.
Perform this task to configure shared keys for servers in an HWTACACS scheme. The keys take
effect on all servers for which a shared key is not individually configured.
To specify a shared key for secure HWTACACS communication:
Step
1.
Enter system view.
2.
Enter HWTACACS scheme
view.
Command
system-view
hwtacacs scheme
hwtacacs-scheme-name
Specify the primary HWTACACS
accounting server:
primary accounting
{ ipv4-address | ipv6
ipv6-address } [ port-number | key
{ cipher | simple } string |
single-connection |
vpn-instance
vpn-instance-name ] *
Specify a secondary HWTACACS
accounting server:
secondary accounting
{ ipv4-address | ipv6
ipv6-address } [ port-number | key
{ cipher | simple } string |
single-connection |
vpn-instance
vpn-instance-name ] *
Command
system-view
hwtacacs scheme
hwtacacs-scheme-name
44
Remarks
N/A
N/A
By default, no accounting servers
are specified.
Two HWTACACS accounting
servers in a scheme, primary or
secondary, cannot have the same
combination of IP address, port
number, and VPN instance.
Remarks
N/A
N/A

Advertisement

Table of Contents
loading

Table of Contents