772 CHAPTER 53: AAA/RADIUS/HWTACACS CONFIGURATION
n
■ Up to 16 HWTACACS schemes can be configured.
■ A scheme can be deleted only when it is not referenced.
Specifying the
HWTACACS
Authentication Servers
Follow these steps to specify the HWTACACS authentication servers:
n
■ The IP addresses of the primary and secondary authentication servers cannot
be the same. Otherwise, the configuration fails.
■ You can remove an authentication server only when no active TCP connection
for sending authentication packets is using it.
Specifying the
HWTACACS
Authorization Servers
Follow these steps to specify the HWTACACS authorization servers:
To do… Use the command… Remarks
Enter system view system-view -
Create a HWTACACS scheme
and enter HWTACACS
scheme view
hwtacacs scheme
hwtacacs-scheme-name
Required
Not defined by default
To do… Use the command… Remarks
Enter system view system-view -
Create a HWTACACS scheme
and enter HWTACACS
scheme view
hwtacacs scheme
hwtacacs-scheme-name
Required
Not defined by default
Configure the IP address and
port of the primary
HWTACACS authentication
server
primary authentication
ip-address [ port-number ]
Required
The defaults are as follows:
0.0.0.0 for the IP address, and
49 for the TCP port.
Configure the IP address and
port of the secondary
HWTACACS authentication
server
secondary authentication
ip-address [ port-number ]
Required
The defaults are as follows:
0.0.0.0 for the IP address, and
49 for the TCP port.
To do… Use the command… Remarks
Enter system view system-view -
Create a HWTACACS scheme
and enter HWTACACS
scheme view
hwtacacs scheme
hwtacacs-scheme-name
Required
Not defined by default
Configure the IP address and
port of the primary
HWTACACS authorization
server
primary authorization
ip-address [ port-number ]
Required
The defaults are as follows:
0.0.0.0 for the IP address, and
49 for the TCP port.
Configure the IP address and
port of the secondary
HWTACACS authorization
server
secondary authorization
ip-address [ port-number ]
Required
The defaults are as follows:
0.0.0.0 for the IP address, and
49 for the TCP port.