2-25
To do… Use the command… Remarks
Enter system view
system-view
—
Create a HWTACACS scheme
and enter its view
hwtacacs scheme
hwtacacs-scheme-name
Required
By default, no HWTACACS
scheme exists.
Set the response timeout time
of TACACS servers
timer response-timeout
seconds
Optional
By default, the response
timeout time is five seconds.
Set the time that the switch
must wait before it can restore
the status of the primary server
to active
timer quiet minutes
Optional
By default, the switch must wait
five minutes before it can
restore the status of the primary
server to active.
Set the real-time accounting
interval
timer realtime-accounting
minutes
Optional
By default, the real-time
accounting interval is 12
minutes.
z To control the interval at which users are charge in real time, you can set the real-time accounting
interval. After the setting, the switch periodically sends online users' accounting information to the
TACACS server at the set interval.
z The real-time accounting interval must be a multiple of 3.
z The setting of real-time accounting interval somewhat depends on the performance of the
TACACS client and server devices: A shorter interval requires higher device performance.
Displaying and Maintaining AAA Configuration
Displaying and Maintaining AAA Configuration
To do… Use the command… Remarks
Display configuration
information about one specific
or all ISP domains
display domain [ isp-name ]
Display information about user
connections
display connection [ access-type { dot1x |
mac-authentication } | domain isp-name |
interface interface-type interface-number | ip
ip-address | mac mac-address | radius-scheme
radius-scheme-name | hwtacacs-scheme
hwtacacs-scheme-name | vlan vlan-id |
ucibindex ucib-index | user-name user-name ]
Display information about local
users
display local-user [ domain isp-name | idle-cut
{ disable | enable } | vlan vlan-id | service-type
{ ftp | lan-access | ssh | telnet | terminal } |
state { active | block } | user-name user-name ]
Available in
any view