Configuring The Local Aaa - Huawei SmartAX MA5603T Configuration Manual

Access module
Hide thumbs Also See for SmartAX MA5603T:
Table of Contents

Advertisement

SmartAX MA5600T/MA5603T/MA5608T Multi-service
Access Module
Commissioning and Configuration Guide
l
l
Table 2-2
Table 2-2 Differences between HWTACACS and RADIUS
HWTACACS
Uses TCP to ensure more reliable network
transmission.
Encrypts the body of HWTACACS packets,
except their header.
Separated authorization and authentication.
Applicable to security control.
Supports authorization of the configuration
commands on the router.

2.4.1 Configuring the Local AAA

This topic describes how to configure the local AAA so that the user authentication can be
performed locally.
Context
l
l
Procedure
Step 1 Configure the AAA authentication scheme.
NOTE
l The authentication scheme specifies how all the users in an Internet service provider (ISP) domain are
authenticated. The system supports up to 16 authentication schemes.
l The system has a default authentication scheme named default. It can be modified, but cannot be deleted.
1.
2.
3.
Issue 01 (2014-04-30)
The MA5600T/MA5603T/MA5608T functions as the client of a remote AAA server, and
is connected to the HWTACACS server through the HWTACACS protocol, implementing
the AAA.
The MA5600T/MA5603T/MA5608T functions as the client of a remote AAA server, and
is connected to the RADIUS server through the RADIUS protocol, implementing the AAA.
The RADIUS protocol, however, does not support authorization.
lists the differences between HWTACACS and RADIUS.
The local AAA configuration is simple, which does not depend on the external server.
The local AAA supports only authentication.
Run the aaa command to enter the AAA mode.
Run the authentication-scheme command to add an authentication scheme.
Run the authentication-mode local command to configure the authentication mode of the
authentication scheme.
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
RADIUS
Uses UDP for transmission.
Encrypts only the password field of the
authenticated packets.
Concurrent processing of authentication and
authorization.
Applicable to accounting.
Does not support the authorization of the
configuration commands on the router.
2 Basic Configurations
227

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Smartax ma5600tSmartax ma5608t

Table of Contents