H3C Technologies H3C SecPath F1000-E User Manual

Page 38

Advertising
background image

30

Step Command

Remarks

9.

Enable command accounting. command accounting

Optional.
By default, command accounting is

disabled. The accounting server
does not record the commands

executed by users.
Command accounting allows the

HWTACACS server to record all
executed commands that are

supported by the device,

regardless of the command

execution result. This helps control
and monitor user operations on the

device. If command accounting is

enabled and command
authorization is not enabled, every

executed command is recorded on

the HWTACACS server. If both
command accounting and

command authorization are

enabled, only the authorized and
executed commands are recorded

on the HWTACACS server.

10.

Exit to system view.

quit

N/A

11.

Configure the authentication
mode.

a.

Enter the ISP domain view:
domain domain-name

b.

Apply the specified AAA
scheme to the domain:

authentication default

{ hwtacacs-scheme

hwtacacs-scheme-name
[ local ] | local | none |

radius-scheme

radius-scheme-name
[ local ] }

c.

Exit to system view:
quit

Optional.
For local authentication, configure
local user accounts.
For RADIUS or HWTACACS
authentication, configure the

RADIUS or HWTACACS scheme

on the device and configure
authentication settings (including

the username and password) on

the server.
For more information about AAA
configuration, see Access Control

Configuration Guide.

12.

Create a local user and enter
local user view.

local-user user-name

By default, no local user exists.

13.

Set the local password.

password { cipher | simple }
password

By default, no local password is
set.

14.

Specify the command level of

the local user.

authorization-attribute level level

Optional.
By default, the command level is 0.

15.

Specify the service type for the
local user.

service-type ssh

By default, no service type is
specified.

16.

Return to system view.

quit

N/A

Advertising