Configuring System Guard.................................................................................................................... 31-2
Configuring System Guard Against IP Attacks.............................................................................. 31-2
Configuring System Guard Against TCN Attacks.......................................................................... 31-2
Enabling Layer 3 Error Control...................................................................................................... 31-3
Configuring CPU Protection .......................................................................................................... 31-3
Displaying and Maintaining System Guard Configuration .................................................................... 31-4
32
AAA Overview ........................................................................................................................................ 32-1
Introduction to AAA ............................................................................................................................... 32-1
Authentication................................................................................................................................ 32-1
Authorization.................................................................................................................................. 32-1
Accounting..................................................................................................................................... 32-2
Introduction to ISP Domain ........................................................................................................... 32-2
Introduction to AAA Services ................................................................................................................ 32-2
Introduction to RADIUS ................................................................................................................. 32-2
Introduction to HWTACACS .......................................................................................................... 32-6
33
AAA Configuration................................................................................................................................. 33-1
AAA Configuration Task List ................................................................................................................. 33-1
Creating an ISP Domain and Configuring Its Attributes ................................................................ 33-2
Configuring an AAA Scheme for an ISP Domain .......................................................................... 33-3
Configuring Dynamic VLAN Assignment....................................................................................... 33-6
Configuring the Attributes of a Local User..................................................................................... 33-8
Cutting Down User Connections Forcibly.................................................................................... 33-10
RADIUS Configuration Task List......................................................................................................... 33-10
Creating a RADIUS Scheme ....................................................................................................... 33-12
Configuring RADIUS Authentication/Authorization Servers ........................................................ 33-12
Configuring Ignorance of Assigned RADIUS Authorization Attributes ........................................ 33-13
Configuring RADIUS Accounting Servers ................................................................................... 33-14
Configuring Shared Keys for RADIUS Messages ....................................................................... 33-15
Configuring the Maximum Number of RADIUS Request Transmission Attempts....................... 33-16
Configuring the Type of RADIUS Servers to be Supported ........................................................ 33-16
Configuring the Status of RADIUS Servers................................................................................. 33-17
Configuring the Attributes of Data to be Sent to RADIUS Servers ............................................. 33-18
Configuring the Local RADIUS Server ........................................................................................ 33-19
Configuring Timers for RADIUS Servers..................................................................................... 33-20
Enabling Sending Trap Message when a RADIUS Server Goes Down ..................................... 33-21
Enabling the User Re-Authentication at Restart Function........................................................... 33-21
HWTACACS Configuration Task List.................................................................................................. 33-23
Creating a HWTACACS Scheme ................................................................................................ 33-23
Configuring TACACS Authentication Servers ............................................................................. 33-23
Configuring TACACS Authorization Servers ............................................................................... 33-24
Configuring TACACS Accounting Servers .................................................................................. 33-25
Configuring Shared Keys for HWTACACS Messages ................................................................ 33-25
Configuring the Attributes of Data to be Sent to TACACS Servers ............................................ 33-26
Configuring the Timers Regarding TACACS Servers ................................................................. 33-27
Displaying and Maintaining AAA Configuration .................................................................................. 33-28
Displaying and Maintaining AAA Configuration........................................................................... 33-28
Displaying and Maintaining RADIUS Protocol Configuration ...................................................... 33-28
xi