3com WX3000 Manuel D’Utilisation

Page de 715
 
2-26 
Displaying and maintaining HWTACACS protocol information 
To do… 
Use the command… 
Remarks 
Display the configuration or 
statistic information about one 
specific or all HWTACACS 
schemes 
display hwtacacs 
hwtacacs-scheme-name statistics ] ] 
Display buffered non-response 
stop-accounting requests 
display stop-accounting-buffer 
hwtacacs-scheme 
hwtacacs-scheme-name  
Available in any view.
Clear HWTACACS message 
statistics 
reset hwtacacs statistics { accounting | 
authentication 
| authorization | all } 
Delete buffered non-response 
stop-accounting requests 
reset stop-accounting-buffer 
hwtacacs-scheme 
hwtacacs-scheme-name  
Available in user 
view. 
 
AAA Configuration Examples 
Remote RADIUS Authentication of Telnet/SSH Users 
 
 
The configuration procedure for remote authentication of SSH users by RADIUS server is similar to that 
for Telnet users. The following text only takes Telnet users as example to describe the configuration 
procedure for remote authentication. 
 
Network requirements 
In the network environment shown in 
, you are required to configure the device so that the 
Telnet users logging into the switching engine are authenticated by the RADIUS server. 
A RADIUS authentication server with IP address 10.110.91.164 is connected to the device.  
On the device, set the shared key it uses to exchange messages with the authentication RADIUS 
server to "aabbcc". 
A IMC server is used as the RADIUS server. You can select extended as the server-type in a 
RADIUS scheme. 
On the RADIUS server, set the shared key it uses to exchange messages with the device to 
"aabbcc," set the authentication port number, and add Telnet user names and login passwords. 
The Telnet user names added to the RADIUS server must be in the format of userid@isp-name if you 
have configured the device to include domain names in the user names to be sent to the RADIUS 
server in the RADIUS scheme.