36
To do… Use the command… Remarks
Enter HWTACACS scheme view
hwtacacs scheme
hwtacacs-scheme-name
—
Set the HWTACACS server
response timeout timer
timer response-timeout seconds
Optional
5 seconds by default
Set the quiet timer for the primary
server
timer quiet minutes
Optional
5 minutes by default
Set the real-time accounting
interval
timer realtime-accounting minutes
Optional
12 minutes by default
NOTE:
• For real-time accounting, a NAS must transmit the accounting information of online users to the
HWTACACS accounting server periodically. If the device does not receive any response to the
information, it does not disconnect the online users forcibly.
• The real-time accounting interval must be a multiple of 3.
• The setting of the real-time accounting interval somewhat depends on the performance of the NAS and
the HWTACACS server. A shorter interval requires higher performance.
Displaying and maintaining HWTACACS
To do… Use the command… Remarks
Display configuration information or
statistics of HWTACACS schemes
display hwtacacs
[ hwtacacs-server-name [ statistics ] ]
[ slot slot-number ] [ | { begin | exclude |
include } regular-expression ]
Available in any view
Display information about buffered
stop-accounting requests that get no
responses
display stop-accounting-buffer
hwtacacs-scheme
hwtacacs-scheme-name [ slot
slot-number ] [ | { begin | exclude |
include } regular-expression ]
Available in any view
Clear HWTACACS statistics
reset hwtacacs statistics { accounting |
all | authentication | authorization }
[ slot slot-number ]
Available in user view
Configuring AAA methods for ISP domains
You configure AAA methods for an ISP domain by referencing configured AAA schemes in ISP domain
view. Each ISP domain has a set of default AAA methods, which are local authentication, local
authorization, and local accounting by default and can be customized. If you do not configure any AAA
methods for an ISP domain, the device uses the system default AAA methods for authentication,
authorization, and accounting of the users in the domain.