HP 6125G HP 6125G & 6125G/XG Blade Switches Security Command Reference - Page 84

hwtacacs scheme

Page 84 highlights

Default level 2: System level Parameters ip-address: IP address in dotted decimal notation. It must be an address of the switch and cannot be 0.0.0.0, 255.255.255.255, a class D address, a class E address, or a loopback address. vpn-instance vpn-instance-name: Specifies the MPLS L3VPN to which the source IP address belongs, where vpn-instance-name is a case-sensitive string of 1 to 31 characters. With a VPN specified, the command specifies a private-network source IP address. With no VPN specified, the command specifies a public-network source IP address. Description Use hwtacacs nas-ip to specify a source IP address for outgoing HWTACACS packets. Use undo hwtacacs nas-ip to remove the configuration. By default, the source IP address of a packet sent to the server is the IP address of the outbound interface. The source IP address of HWTACACS packets that a NAS sends must match the IP address of the NAS that is configured on the HWTACACS server. An HWTACACS server identifies a NAS by IP address. Upon receiving an HWTACACS packet, an HWTACACS server checks whether the source IP address of the packet is the IP address of any managed NAS. If yes, the server processes the packet. If not, the server drops the packet. You can specify up to one public-network source IP address and 15 private-network source IP addresses. A newly specified public-network source IP address overwrites the previous one. Each VPN can have only one private-network source IP address specified. A private-network source IP address newly specified for a VPN overwrites the previous one. The setting configured by the nas-ip command in HWTACACS scheme view is only for the HWTACACS scheme, whereas that configured by the hwtacacs nas-ip command in system view is for all HWTACACS schemes. The setting in HWTACACS scheme view takes precedence. Related commands: nas-ip. Examples # Set the IP address for the switch to use as the source address of the HWTACACS packets to 129.10.10.1. system-view [Sysname] hwtacacs nas-ip 129.10.10.1 hwtacacs scheme Syntax hwtacacs scheme hwtacacs-scheme-name View undo hwtacacs scheme hwtacacs-scheme-name System view Default level 3: Manage level Parameters hwtacacs-scheme-name: HWTACACS scheme name, a case-insensitive string of 1 to 32 characters. 75

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291

75
Default level
2: System level
Parameters
ip-address
: IP address in dotted decimal notation. It must be an address of the switch and cannot be
0.0.0.0, 255.255.255.255, a class D address, a class E address, or a loopback address.
vpn-instance
vpn-instance-name
: Specifies the MPLS L3VPN to which the source IP address belongs,
where
vpn-instance-name
is a case-sensitive string of 1 to 31 characters. With a VPN specified, the
command specifies a private-network source IP address. With no VPN specified, the command specifies
a public-network source IP address.
Description
Use
hwtacacs nas-ip
to specify a source IP address for outgoing HWTACACS packets.
Use
undo hwtacacs nas-ip
to remove the configuration.
By default, the source IP address of a packet sent to the server is the IP address of the outbound interface.
The source IP address of HWTACACS packets that a NAS sends must match the IP address of the NAS
that is configured on the HWTACACS server. An HWTACACS server identifies a NAS by IP address.
Upon receiving an HWTACACS packet, an HWTACACS server checks whether the source IP address of
the packet is the IP address of any managed NAS. If yes, the server processes the packet. If not, the server
drops the packet.
You can specify up to one public-network source IP address and 15 private-network source IP addresses.
A newly specified public-network source IP address overwrites the previous one. Each VPN can have only
one private-network source IP address specified. A private-network source IP address newly specified for
a VPN overwrites the previous one.
The setting configured by the
nas-ip
command in HWTACACS scheme view is only for the HWTACACS
scheme, whereas that configured by the
hwtacacs nas-ip
command in system view is for all HWTACACS
schemes. The setting in HWTACACS scheme view takes precedence.
Related commands:
nas-ip
.
Examples
# Set the IP address for the switch to use as the source address of the HWTACACS packets to
129.10.10.1
.
<Sysname> system-view
[Sysname] hwtacacs nas-ip 129.10.10.1
hwtacacs scheme
Syntax
hwtacacs scheme
hwtacacs-scheme-name
undo hwtacacs scheme
hwtacacs-scheme-name
View
System view
Default level
3: Manage level
Parameters
hwtacacs-scheme-name
: HWTACACS scheme name, a case-insensitive string of 1 to 32 characters.