Operation Manual – AAA & RADIUS & HWTACACS
H3C S3610&S5510 Series Ethernet Switches Table of Contents
i
Table of Contents
Chapter 1 AAA & RADIUS & HWTACACS Configuration..........................................................1-1
1.1 Overview............................................................................................................................1-1
1.1.1 Introduction to AAA.................................................................................................1-1
1.1.2 Introduction to ISP Domain.....................................................................................1-2
1.1.3 Introduction to RADIUS...........................................................................................1-2
1.1.4 Introduction to HWTACACS....................................................................................1-8
1.2 Configuration Tasks.........................................................................................................1-12
1.3 AAA Configuration ........................................................................................................... 1-14
1.3.1 Configuration Prerequisites...................................................................................1-15
1.3.2 Creating an ISP Domain .......................................................................................1-15
1.3.3 Configuring the Attributes of an ISP Domain........................................................ 1-16
1.3.4 Configuring AAA Authentication of an ISP Domain ..............................................1-16
1.3.5 Configuring AAA Authorization of an ISP Domain................................................1-18
1.3.6 Configuring AAA Accounting of an ISP Domain ...................................................1-20
1.3.7 Configuring the Attributes of a Local User............................................................ 1-22
1.3.8 Cutting Down User Connections Forcibly.............................................................1-24
1.4 RADIUS Configuration..................................................................................................... 1-25
1.4.1 Creating a RADIUS Scheme................................................................................. 1-25
1.4.2 Configuring RADIUS Authentication/Authorization Servers..................................1-26
1.4.3 Configuring RADIUS Accounting Servers and Related Parameters.....................1-27
1.4.4 Configuring Shared Keys for RADIUS Packets .................................................... 1-28
1.4.5 Configuring the Maximum Number of Transmission Attempts of RADIUS Packets1-29
1.4.6 Configuring the Supported RADIUS Server Type................................................. 1-30
1.4.7 Configuring the Status of RADIUS Servers ..........................................................1-30
1.4.8 Configuring the Attributes for Data to be Sent to RADIUS Servers......................1-31
1.4.9 Configuring a Local RADIUS Server.....................................................................1-32
1.4.10 Configuring the Timers of RADIUS Servers........................................................1-33
1.5 HWTACACS Configuration..............................................................................................1-34
1.5.1 Creating a HWTACACS Scheme..........................................................................1-34
1.5.2 Configuring HWTACACS Authentication Servers................................................. 1-35
1.5.3 Configuring HWTACACS Authorization Servers................................................... 1-36
1.5.4 Configuring HWTACACS Accounting Servers...................................................... 1-36
1.5.5 Configuring Shared Keys for RADIUS Packets .................................................... 1-37
1.5.6 Configuring the Attributes for Data to be Sent to TACACS Servers.....................1-38
1.5.7 Configuring the Timers of TACACS Servers.........................................................1-39
1.6 Displaying and Maintaining AAA & RADIUS & HWTACACS Information.......................1-40
1.7 AAA & RADIUS & HWTACACS Configuration Examples............................................... 1-42
1.7.1 Remote RADIUS Authentication of Telnet/SSH Users......................................... 1-42