Hwtacacs Scheme - HP A-U200 Command Reference Manual

Unified threat management products
Table of Contents

Advertisement

Description
Use the hwtacacs nas-ip command to specify a source IP address for outgoing HWTACACS packets.
Use the undo hwtacacs nas-ip command to remove the configuration.
By default, the source IP address of a packet sent to the server is the IP address of the outbound interface.
The source IP address of HWTACACS packets that a NAS sends must match the IP address of the NAS
that is configured on the HWTACACS server. An HWTACACS server identifies a NAS by IP address.
Upon receiving an HWTACACS packet, an HWTACACS server checks whether the source IP address of
the packet is the IP address of any managed NAS. If yes, the server processes the packet. If not, the server
drops the packet.
NOTE:
The setting configured by the nas-ip command in HWTACACS scheme view is only for the HWTACACS
scheme, whereas that configured by the hwtacacs nas-ip command in system view is for all HWTACACS
schemes. The setting in HWTACACS scheme view takes precedence.
Related commands: nas-ip.
Examples
# Set the IP address for the device to use as the source address of the HWTACACS packets to 129.10.10.1.
<Sysname> system-view
[Sysname] hwtacacs nas-ip 129.10.10.1

hwtacacs scheme

Syntax
hwtacacs scheme hwtacacs-scheme-name
undo hwtacacs scheme hwtacacs-scheme-name
View
System view
Default level
3: Manage level
Parameters
hwtacacs-scheme-name: HWTACACS scheme name, a case-insensitive string of 1 to 32 characters.
Description
Use the hwtacacs scheme command to create an HWTACACS scheme and enter HWTACACS scheme
view.
Use the undo hwtacacs scheme command to delete an HWTACACS scheme.
By default, no HWTACACS scheme exists.
An HWTACACS scheme can be referenced by more than one ISP domain at the same time.
An HWTACACS scheme referenced by ISP domains cannot be removed.
Examples
# Create an HWTACACS scheme named hwt1 and enter HWTACACS scheme view.
124

Advertisement

Table of Contents
loading

Table of Contents