ii
Creating an HWTACACS scheme ··········································································································· 39
Specifying the HWTACACS authentication servers ················································································· 39
Specifying the HWTACACS authorization servers ··················································································· 40
Specifying the HWTACACS accounting servers ······················································································ 40
Specifying the shared keys for secure HWTACACS communication ······················································ 41
Specifying an MPLS L3VPN instance for the scheme ············································································· 42
Setting HWTACACS timers ······················································································································ 42
Specifying the source IP address of outgoing HWTACACS packets ······················································· 43
Setting the username format and traffic statistics units ············································································ 44
Setting the DSCP priority for HWTACACS packets ················································································· 45
Specifying the action to take for AAA requests if all HWTACACS servers are blocked ··························· 45
Configuring HWTACACS stop-accounting packet buffering ···································································· 46
Verifying and maintaining HWTACACS ··································································································· 46
Creating an ISP domain ··································································································································· 47
About ISP domains ·································································································································· 47
Restrictions and guidelines for ISP domain configuration ········································································ 47
Creating an ISP domain ··························································································································· 47
Specifying the default ISP domain ··········································································································· 48
Specifying an ISP domain for users that are assigned to nonexistent domains ······································ 48
Configuring ISP domain attributes ··················································································································· 48
Setting ISP domain status ························································································································ 48
Configuring authorization attributes for an ISP domain············································································ 49
Including the idle timeout period in the user online duration to be sent to the server ······························ 49
Configuring AAA methods for an ISP domain ·································································································· 49
Configuring authentication methods for an ISP domain ··········································································· 49
Configuring authorization methods for an ISP domain ············································································· 51
Configuring accounting methods for an ISP domain ················································································ 52
Verifying and maintaining ISP domains ··································································································· 54
Setting the maximum number of concurrent login users ·················································································· 54
Configuring a NAS-ID······································································································································· 54
About NAS-IDs ········································································································································· 54
Setting the NAS-ID in an ISP domain ······································································································ 54
Configuring the device ID ································································································································· 54
Enabling password change prompt logging ····································································································· 55
Configuring an EAP profile ······························································································································· 56
Configuring user online and offline recording··································································································· 57
About user online and offline recording···································································································· 57
Restrictions and guidelines for user online and offline recording configuration ······································· 57
Enabling user online failure recording ······································································································ 57
Enabling user offline recording ················································································································· 57
Verifying and maintaining user online and offline records········································································ 58
Configuring the connection recording policy ···································································································· 59
About the connection recording policy ····································································································· 59
Restrictions and guidelines ······················································································································ 59
Procedure ················································································································································· 59
Verifying and maintaining the connection recording policy ······································································ 59
Configuring the AAA test feature······················································································································ 60
AAA configuration examples ···························································································································· 63
Example: Configuring authentication and authorization for SSH users by a RADIUS server ·················· 63
Example: Configuring local authentication and authorization for SSH users ··········································· 66
Example: Configuring AAA for SSH users by an HWTACACS server ····················································· 68
Troubleshooting AAA ······································································································································· 69
RADIUS authentication failure ················································································································· 69
RADIUS packet delivery failure ················································································································ 70
RADIUS accounting error ························································································································· 70
Troubleshooting HWTACACS ·················································································································· 71
Appendixes ······················································································································································ 71
Appendix A Commonly used RADIUS attributes ···················································································· 71
Appendix B Descriptions of commonly used standard RADIUS attributes ············································· 72
Appendix C RADIUS subattributes (vendor ID 25506) ··········································································· 74
Appendix D HWTACACS attributes ········································································································ 77