59
Ste
Command
Remarks
5. Enable command accounting.
command
accounting
Optional.
⢠By default, command accounting is
disabled. The accounting server does not
record the commands executed by users.
⢠Command accounting allows the
HWTACACS server to record all executed
commands that are supported by the
device, regardless of the command
execution result. This helps control and
monitor user operations on the device. If
command accounting is enabled and
command authorization is not enabled,
every executed command is recorded on the
HWTACACS server. If both command
accounting and command authorization are
enabled, only the authorized and executed
commands are recorded on the
HWTACACS server.
⢠Configure the AAA accounting server
before enabling command accounting.
6. Exit to system view quit ā
7. Configure
the
authenticatio
n mode.
Enter the default
ISP domain view.
domain
domain-name
Optional.
By default, the AAA scheme is local.
If you specify the local AAA scheme, perform
the configuration concerning local user as well.
If you specify an existing scheme by providing
the radius-scheme-name argument, perform the
following configuration as well:
⢠For RADIUS and HWTACACS
configuration, see Security Configuration
Guide.
⢠Configure the username and password on
the AAA server. (For more information, see
Security Configuration Guide.)
Apply the
specified AAA
scheme to the
domain.
authentication
default { hwtacacs-
scheme hwtacacs-
scheme-name
[ local ] | local |
none | radius-
scheme radius-
scheme-name
[ local ] }
Return to system
view.
quit
8. Create a local user and enter
local user view.
local-user
user-name
Required.
By default, no local user exists.
9. Set the authentication password
for the local user.
password { cipher
| simple }
password
Required.
10. Specifies the command level of
the local user.
authorization-attri
bute level level
Optional.
By default, the command level is 0.
11. Specify the service type for the
local user.
service-type
terminal
Required.
By default, no service type is specified.
12. Configuring common settings for
modem login.
ā
Optional.
See āConfiguring common settings for modem
login (optional).ā