HP 10500 Series Configuration Manual page 43

Security configuration guide
Hide thumbs Also See for 10500 Series:
Table of Contents

Advertisement

Creating an HWTACACS scheme
The HWTACACS protocol is configured on a per-scheme basis. Before performing other HWTACACS
configurations, you must create an HWTACACS scheme and enter HWTACACS scheme view.
You can configure up to 16 HWTACACS schemes, and cannot delete the schemes that are referenced.
To create an HWTACACS scheme and enter HWTACACS scheme view:
Step
1.
Enter system view.
2.
Create an HWTACACS scheme and
enter HWTACACS scheme view.
Specifying the HWTACACS authentication servers
You can specify one primary authentication server and one secondary authentication server for an
HWTACACS scheme. When the primary server is not available, the secondary server is used. If
redundancy is not required, specify only the primary server.
Follow these guidelines when you specify HWTACACS authentication servers:
An HWTACACS server can function as the primary authentication server of one scheme and as the
secondary authentication server of another scheme at the same time.
The IP addresses of the primary and secondary authentication servers cannot be the same.
Otherwise, the configuration fails.
You can remove an authentication server only when no active TCP connection for sending
authentication packets is using it.
To specify HWTACACS authentication servers for an HWTACACS scheme:
Step
1.
Enter system view.
2.
Enter HWTACACS scheme
view.
3.
Specify HWTACACS
authentication servers.
Specifying the HWTACACS authorization servers
You can specify one primary authorization server and one secondary authorization server for an
HWTACACS scheme. When the primary server is not available, the secondary server is used. In a
scenario where redundancy is not required, specify only the primary server.
Follow these guidelines when you specify HWTACACS accounting servers:
Command
system-view
hwtacacs scheme
hwtacacs-scheme-name
Command
system-view
hwtacacs scheme hwtacacs-scheme-name
Specify the primary HWTACACS
authentication server:
primary authentication ip-address
[ port-number | vpn-instance
vpn-instance-name ] *
Specify a secondary HWTACACS
authentication server:
secondary authentication ip-address
[ port-number | vpn-instance
vpn-instance-name ] *
33
Remarks
N/A
Not defined by default.
Remarks
N/A
N/A
Configure at least one
command.
No authentication server is
specified by default.

Advertisement

Table of Contents
loading

Table of Contents