H3C S5120-HI Security Configuration Manual page 50

Hide thumbs Also See for S5120-HI:
Table of Contents

Advertisement

Specifying the HWTACACS authentication servers
For versions earlier than Release 5206, you can specify one primary authentication server and one
secondary authentication server for an HWTACACS scheme. When the primary server is not available,
the secondary server is used.
For Release 5206 and later versions, you can specify one primary authentication server and up to 16
secondary authentication servers for an HWTACACS scheme. When the primary server is not available,
the device tries to communicate with the secondary servers in the order they are configured. Once a
secondary server in active state is found, the device immediately uses it for HWTACACS authentication.
If redundancy is not required, specify only the primary server.
Follow these guidelines when you specify HWTACACS authentication servers:
An HWTACACS server can function as the primary authentication server of one scheme and as the
secondary authentication server of another scheme at the same time.
The IP addresses of the primary and secondary authentication servers cannot be the same.
Otherwise, the configuration fails.
You can remove an authentication server only when no active TCP connection for sending
authentication packets is using it.
To specify HWTACACS authentication servers for an HWTACACS scheme:
Step
1.
Enter system view.
2.
Enter HWTACACS
scheme view.
3.
Specify HWTACACS
authentication servers.
Specifying the HWTACACS authorization servers
For versions earlier than Release 5206, you can specify one primary authorization server and one
secondary authorization server for an HWTACACS scheme. When the primary server is not available,
the secondary server is used.
For Release 5206 and later versions, you can specify one primary authorization server and up to 16
secondary authorization servers for an HWTACACS scheme. When the primary server is not available,
the device tries to communicate with the secondary servers in the order they are configured. Once a
secondary server in active state is found, the device immediately uses it for HWTACACS authorization.
If redundancy is not required, specify only the primary server.
Follow these guidelines when you specify HWTACACS authorization servers:
An HWTACACS server can function as the primary authorization server of one scheme and as the
secondary authorization server of another scheme at the same time.
Command
system-view
hwtacacs scheme hwtacacs-scheme-name
Specify the primary HWTACACS
authentication server:
primary authentication ip-address
[ port-number | key [ cipher | simple ]
key ] *
Specify the secondary HWTACACS
authentication server:
secondary authentication ip-address
[ port-number | key [ cipher | simple ]
key ] *
33
Remarks
N/A
N/A
Configure at least one
command.
No authentication server is
specified by default.
The key [ cipher | simple ] key
option is available in Release
5206 and later versions.

Advertisement

Table of Contents
loading

Table of Contents