Hwtacacs Configuration - H3C S7500 Series Operation Manual

Hide thumbs Also See for S7500 Series:
Table of Contents

Advertisement

Operation Manual – AAA & RADIUS & HWTACACS & EAD
H3C S7500 Series Ethernet Switches
1)
The switch generates an Accounting-On packet, which mainly contains the
following information: NAS-ID, NAS-IP address (source IP address), and session
ID.
2)
The switch sends the Accounting-On packet to CAMS at regular intervals.
3)
Once the CAMS receives the Accounting-On packet, it sends a response to the
switch. At the same time it finds and deletes the original online information of the
users who access the network through the switch before the restart according to
the information contained in this packet (NAS-ID, NAS-IP address and session ID),
and ends the accounting of the users based on the last accounting update packet.
4)
Once the switch receives the response from the CAMS, it stops sending other
Accounting-On packets.
5)
If the switch does not receive any response from the CAMS after the number of the
Accounting-On packets it has sent reaches the configured maximum number, it
does not send any more Accounting-On packets.
Note:
The switch can automatically generate the main attributes (NAS-ID, NAS-IP address
and session ID) in the Accounting-On packets. However, you can also manually
configure the NAS-IP address with the nas-ip command. If you choose to manually
configure the attribute, be sure to configure an appropriate and legal IP address. If this
attribute is not configured, the switch will automatically use the IP address of the VLAN
interface as the NAS-IP address.
Table 1-22 Enable the user re-authentication upon device restart function
Enter system view
Enter RADIUS scheme
view
Enable the user
re-authentication upon
device restart function

1.5 HWTACACS Configuration

This section covers these topics:
Creating a HWTACACS Scheme
To do...
Use the command...
system-view
radius scheme
radius-scheme-name
accounting-on enable
[ send times | interval
interval ]
Chapter 1 AAA & RADIUS & HWTACACS
By default, this function is
disabled, and the system
can send at most 15
Accounting-On packets
consecutively at intervals of
three seconds.
1-32
Configuration
Remarks

Advertisement

Table of Contents
loading

Table of Contents