HP 6125XLG R2306-HP 6125XLG Blade Switch Security Configuration Guide - Page 45

Displaying and maintaining HWTACACS, state by first checking

Page 45 highlights

search process continues until the device finds an available secondary server or has checked all secondary servers in active state. If the quiet timer of a server expires, the status of the server changes back to active, but the device does not check the server again during the authentication or accounting process. If no server is found reachable during one search process, the device considers the authentication or accounting attempt a failure. • If you remove an authentication or accounting server in use, the communication of the device with the server soon times out, and the device looks for a server in active state by first checking the primary server and then secondary servers in the order they are configured. • When the primary server and secondary servers are all in blocked state, the device does not communicate with any server. • If one server is in active state and all the others are in blocked state, the device tries to communicate with the server in active state only, even if the server is unavailable. • If the status of an HWTACACS server changes automatically, the device changes the status of this server accordingly in all HWTACACS schemes in which this server is specified. To set HWTACACS timers: Step 1. Enter system view. Command system-view Remarks N/A 2. Enter HWTACACS scheme view. hwtacacs scheme hwtacacs-scheme-name N/A 3. Set the HWTACACS server response timeout timer. timer response-timeout seconds By default, the HWTACACS server response timeout timer is 5 seconds. By default, the real-time accounting interval is 12 minutes. 4. Set the real-time accounting A short interval helps improve interval. timer realtime-accounting minutes accounting precision but requires many system resources. When there are 1000 or more users, set a longer interval. 5. Set the server quiet timer. timer quiet minutes By default, the server quiet timer is 5 minutes. Displaying and maintaining HWTACACS Execute the display command in any view and the reset command in user view. Purpose Display the configuration or server statistics of HWTACACS schemes. Clear HWTACACS statistics. Command display hwtacacs scheme [ hwtacacs-server-name [ statistics ] reset hwtacacs statistics { accounting | all | authentication | authorization } 36

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276

36
search process continues until the device finds an available secondary server or has checked all
secondary servers in
active
state.
If the quiet timer of a server expires, the status of the server changes back to
active
, but the device
does not check the server again during the authentication or accounting process.
If no server is found reachable during one search process, the device considers the authentication
or accounting attempt a failure.
If you remove an authentication or accounting server in use, the communication of the device with
the server soon times out, and the device looks for a server in
active
state by first checking the
primary server and then secondary servers in the order they are configured.
When the primary server and secondary servers are all in
blocked
state, the device does not
communicate with any server.
If one server is in
active
state and all the others are in
blocked
state, the device tries to communicate
with the server in
active
state only, even if the server is unavailable.
If the status of an HWTACACS server changes automatically, the device changes the status of this
server accordingly in all HWTACACS schemes in which this server is specified.
To set HWTACACS timers:
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter HWTACACS scheme
view.
hwtacacs scheme
hwtacacs-scheme-name
N/A
3.
Set the HWTACACS server
response timeout timer.
timer response-timeout
seconds
By default, the HWTACACS server
response timeout timer is 5 seconds.
4.
Set the real-time accounting
interval.
timer realtime-accounting
minutes
By default, the real-time accounting
interval is 12 minutes.
A short interval helps improve
accounting precision but requires
many system resources. When there
are 1000 or more users, set a longer
interval.
5.
Set the server quiet timer.
timer quiet
minutes
By default, the server quiet timer is 5
minutes.
Displaying and maintaining HWTACACS
Execute the
display
command in any view and the
reset
command in user view.
Purpose
Command
Display the configuration or server
statistics of HWTACACS schemes.
display hwtacacs scheme
[
hwtacacs-server-name
[
statistics
]
Clear HWTACACS statistics.
reset hwtacacs statistics
{
accounting
|
all
|
authentication
|
authorization
}