3Com Switch 4800G 24-Port Configuration Manual page 773

Switch 4800g family 24-port, pwr 24-port, 48-port, pwr 48-port, 24-port sfp
Hide thumbs Also See for Switch 4800G 24-Port:
Table of Contents

Advertisement

n
Specifying the
HWTACACS Accounting
Servers
n
Setting the Shared Key
for HWTACACS Packets
The IP addresses of the primary and secondary authorization servers cannot be
the same. Otherwise, the configuration fails.
You can remove an authorization server only when no active TCP connection
for sending authorization packets is using it.
Follow these steps to specify the HWTACACS accounting servers and perform
related configurations:
To do...
Enter system view
Create a HWTACACS scheme
and enter HWTACACS
scheme view
Configure the IP address and
port of the primary
HWTACACS accounting
server
Configure the IP address and
port of the secondary
HWTACACS accounting
server
Enable the device to buffer
stop-accounting requests
getting no responses
Set the maximum number of
stop-accounting request
transmission attempts
The IP addresses of the primary and secondary accounting servers cannot be
the same. Otherwise, the configuration fails.
You can remove an accounting server only when no active TCP connection for
sending accounting packets is using it.
Currently, HWTACACS does not support keeping accounts on FTP users.
When using a HWTACACS server as an AAA server, you can set a key to secure the
communications between the device and the HWTACACS server.
The HWTACACS client and HWTACACS server use the MD5 algorithm to encrypt
packets exchanged between them and a shared key to verify the packets. Only
when the same key is used can they properly receive the packets and make
responses.
Follow these steps to set the shared key for HWTACACS packets:
To do...
Enter system view
Create a HWTACACS scheme
and enter HWTACACS
scheme view
Use the command...
system-view
hwtacacs scheme
hwtacacs-scheme-name
primary accounting
ip-address [ port-number ]
secondary accounting
ip-address [ port-number ]
stop-accounting-buffer
enable
retry stop-accounting
retry-times
Use the command...
system-view
hwtacacs scheme
hwtacacs-scheme-name
Configuring HWTACACS
Remarks
-
Required
Not defined by default
Required
The defaults are as follows:
0.0.0.0 for the IP address, and
49 for the TCP port.
Required
The defaults are as follows:
0.0.0.0 for the IP address, and
49 for the TCP port.
Optional
Enabled by default
Optional
100 by default
Remarks
-
Required
Not defined by default
773

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents