Aaa For Telnet Users By Separate Servers - H3C S7500E Series Operation Manual

S7500e series
Hide thumbs Also See for H3C S7500E Series:
Table of Contents

Advertisement

Operation Manual – AAA RADIUS HWTACACS
H3C S7500E Series Ethernet Switches
[Switch-hwtacacs-hwtac] primary authorization 10.1.1.1 49
[Switch-hwtacacs-hwtac] primary accounting 10.1.1.1 49
[Switch-hwtacacs-hwtac] key authentication expert
[Switch-hwtacacs-hwtac] key authorization expert
[Switch-hwtacacs-hwtac] key accounting expert
[Switch-hwtacacs-hwtac] user-name-format without-domain
[Switch-hwtacacs-hwtac] quit
# Apply the AAA schemes to the domain.
[Switch] domain bbb
[Switch-isp-bbb] authentication login hwtacacs-scheme hwtac
[Switch-isp-bbb] authorization login hwtacacs-scheme hwtac
[Switch-isp-bbb] accounting login hwtacacs-scheme hwtac
[Switch-isp-bbb] quit
# You can achieve the same purpose by setting AAA schemes for all types of users.
[Switch] domain bbb
[Switch-isp-bbb] authentication default hwtacacs-scheme hwtac
[Switch-isp-bbb] authorization default hwtacacs-scheme hwtac
[Switch-isp-bbb] accounting default hwtacacs-scheme hwtac
[Switch-isp-hwtacacs] accounting default hwtacacs-scheme hwtac
When telneting into the switch, a user enters username userid@bbb for authentication
using domain bbb.

1.7.2 AAA for Telnet Users by Separate Servers

I. Network requirements
As shown in
HWTACACS authorization, and RADIUS accounting services to Telnet users. The user
name and the password for Telnet users are both hello.
The HWTACACS server is used for authorization. Its IP address is 10.1.1.2. On the
switch, set the shared keys for packets exchanged with the TACACS server to expert.
Configure the switch to remove the domain name from a user name before sending the
user name to the HWTACACS server.
The RADIUS server is used for accounting. Its IP address is 10.1.1.1. On the switch,
set the shared keys for packets exchanged with the RADIUS server to expert.
Configure the switch to remove the domain name from a user name before sending the
user name to the HWTACACS server.
Figure
1-8, configure the switch to provide local authentication,
1-40
Chapter 1 AAA/RADIUS/HWTACACS
Configuration

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

S7502eS7503eS7506eS7510eS7506e-v

Table of Contents