Troubleshooting Aaa; Troubleshooting Radius Configuration - H3C S5100-SI Series Operation Manual

Hide thumbs Also See for S5100-SI Series:
Table of Contents

Advertisement

Operation Manual – AAA
H3C S5100-SI/EI Series Ethernet Switches
II. Network diagram
Telnet user
Figure 2-3 Remote HWTACACS authentication and authorization of Telnet users
III. Configuration procedure
# Add a Telnet user.
(Omitted here)
# Configure a HWTACACS scheme.
<Sysname> system-view
[Sysname] hwtacacs scheme hwtac
[Sysname-hwtacacs-hwtac] primary authentication 10.110.91.164 49
[Sysname-hwtacacs-hwtac] primary authorization 10.110.91.164 49
[Sysname-hwtacacs-hwtac] key authentication aabbcc
[Sysname-hwtacacs-hwtac] key authorization aabbcc
[Sysname-hwtacacs-hwtac] user-name-format without-domain
[Sysname-hwtacacs-hwtac] quit
# Configure the domain name of the HWTACACS scheme to hwtac.
[Sysname] domain hwtacacs
[Sysname-isp-hwtacacs] scheme hwtacacs-scheme hwtac

2.6 Troubleshooting AAA

2.6.1 Troubleshooting RADIUS Configuration

The RADIUS protocol operates at the application layer in the TCP/IP protocol suite.
This protocol prescribes how the switch and the RADIUS server of the ISP exchange
user information with each other.
Symptom 1: User authentication/authorization always fails.
Possible reasons and solutions:
The username is not in the userid@isp-name or userid.isp-name format, or the
default ISP domain is not correctly specified on the switch — Use the correct
username format, or set a default ISP domain on the switch.
Authentication server
10.110.91.164/16
Internet
2-37
Chapter 2 AAA Configuration

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents