33
To do… Use the command… Remarks
Specify the secondary
HWTACACS authorization
server
secondary authorization ip-address
[ port-number | key [ cipher | simple ]
key ] *
No authorization server is
specified by default.
NOTE:
• If both the primary and secondary authorization servers are specified, the secondary one is used when
the primary one is not reachable.
• If redundancy is not required, specify only the primary HWTACACS authorization server.
• The IP addresses of the primary and secondary authorization servers cannot be the same. Otherwise,
the configuration fails.
• You can remove an authorization server only when no active TCP connection for sendin
authorization
packets is using it.
Specifying the HWTACACS accounting servers
Follow these steps to specify the HWTACACS accounting servers and perform related configurations:
To do… Use the command… Remarks
Enter system view
system-view
—
Enter HWTACACS scheme view
hwtacacs scheme
hwtacacs-scheme-name
—
Specify the primary
HWTACACS accounting server
primary accounting ip-address
[ port-number | key [ cipher |
simple ] key ] *
Required
Configure at least one command.
No accounting server is specified by
default.
Specify the secondary
HWTACACS accounting server
secondary accounting ip-address
[ port-number | key [ cipher |
simple ] key ] *
Enable the device to buffer
stop-accounting requests getting
no responses
stop-accounting-buffer enable
Optional
Enabled by default
Set the maximum number of
stop-accounting request
transmission attempts
retry stop-accounting retry-times
Optional
100 by default
NOTE:
• If both the primary and secondary accountin
servers are specified, the secondary server is used when
the primary server is not reachable.
• If redundancy is not required, specify only the primary HWTACACS accounting server.
• The IP addresses of the primary and secondary accountin
servers cannot be the same. Otherwise, the
configuration will fail.
• You can remove an accounting server only when no active TCP connection for sending accounting
packets is using it.
• HWTACACS does not support keeping accounts on FTP users.