HP 6125XLG R2306-HP 6125XLG Blade Switch Security Configuration Guide - Page 41

Specifying the HWTACACS authorization servers, active, Command, Remarks

Page 41 highlights

Specifying the HWTACACS authorization servers You can specify one primary authorization server and up to 16 secondary authorization servers for an HWTACACS scheme. When the primary server is not available, the device tries to communicate with the secondary servers in the order they are configured, and communicates with the first secondary server in active state. If no redundancy is needed, specify only the primary server. An HWTACACS server can function as the primary authorization server of one scheme and as the secondary authorization server of another scheme at the same time. To specify HWTACACS authorization servers for an HWTACACS scheme: Step 1. Enter system view. 2. Enter HWTACACS scheme view. 3. Specify HWTACACS authorization servers. Command Remarks system-view N/A hwtacacs scheme hwtacacs-scheme-name • Specify the primary HWTACACS authorization server: primary authorization { ipv4-address | ipv6 ipv6-address } [ port-number | key { cipher | simple } string | vpn-instance vpn-instance-name ] * • Specify a secondary HWTACACS authorization server: secondary authorization { ipv4-address | ipv6 ipv6-address } [ port-number | key { cipher | simple } string | vpn-instance vpn-instance-name ] * N/A Configure at least one command. By default, no authorization server is specified. Two HWTACACS authorization servers in a scheme, primary or secondary, cannot have the same combination of IP address, port number, and VPN. Specifying the HWTACACS accounting servers You can specify one primary accounting server and up to 16 secondary accounting servers for an HWTACACS scheme. When the primary server is not available, the device tries to communicate with the secondary servers in the order they are configured, and communicates with the first secondary server in active state. If no redundancy is needed, specify only the primary server. An HWTACACS server can function as the primary accounting server of one scheme and as the secondary accounting server of another scheme at the same time. HWTACACS does not support accounting for FTP users. To specify HWTACACS accounting servers for an HWTACACS scheme: Step 1. Enter system view. 2. Enter HWTACACS scheme view. Command system-view hwtacacs scheme hwtacacs-scheme-name Remarks N/A N/A 32

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276

32
Specifying the HWTACACS authorization servers
You can specify one primary authorization server and up to 16 secondary authorization servers for an
HWTACACS scheme. When the primary server is not available, the device tries to communicate with the
secondary servers in the order they are configured, and communicates with the first secondary server in
active
state. If no redundancy is needed, specify only the primary server. An HWTACACS server can
function as the primary authorization server of one scheme and as the secondary authorization server of
another scheme at the same time.
To specify HWTACACS authorization servers for an HWTACACS scheme:
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter HWTACACS
scheme view.
hwtacacs scheme
hwtacacs-scheme-name
N/A
3.
Specify HWTACACS
authorization servers.
Specify the primary HWTACACS
authorization server:
primary authorization
{
ipv4-address
|
ipv6
ipv6-address
}
[
port-number
|
key
{
cipher
|
simple
}
string
|
vpn-instance
vpn-instance-name
] *
Specify a secondary HWTACACS
authorization server:
secondary authorization
{
ipv4-address
|
ipv6
ipv6-address
}
[
port-number
|
key
{
cipher
|
simple
}
string
|
vpn-instance
vpn-instance-name
] *
Configure at least one command.
By default, no authorization server
is specified.
Two HWTACACS authorization
servers in a scheme, primary or
secondary, cannot have the same
combination of IP address, port
number, and VPN.
Specifying the HWTACACS accounting servers
You can specify one primary accounting server and up to 16 secondary accounting servers for an
HWTACACS scheme. When the primary server is not available, the device tries to communicate with the
secondary servers in the order they are configured, and communicates with the first secondary server in
active
state. If no redundancy is needed, specify only the primary server. An HWTACACS server can
function as the primary accounting server of one scheme and as the secondary accounting server of
another scheme at the same time.
HWTACACS does not support accounting for FTP users.
To specify HWTACACS accounting servers for an HWTACACS scheme:
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter HWTACACS
scheme view.
hwtacacs scheme
hwtacacs-scheme-name
N/A