33-27
Generally, the access users are named in the
userid@isp-name
or
userid.isp-name
format. Where,
isp-name
after the “
@
” or “.” character represents the ISP domain name. If the TACACS server does not
accept the usernames that carry ISP domain names, it is necessary to remove domain names from
usernames before they are sent to TACACS server.
Configuring the Timers Regarding TACACS Servers
Follow these steps to configure the timers regarding TACACS servers:
To do…
Use the command…
Remarks
Enter system view
—
system-view
Required
Create a HWTACACS scheme
and enter its view
hwtacacs scheme
hwtacacs-scheme-name
By default, no HWTACACS
scheme exists.
Optional
Set the response timeout time
of TACACS servers
timer response-timeout
seconds
By default, the response
timeout time is five seconds.
Optional
Set the time that the switch
must wait before it can restore
the status of the primary server
to active
By default, the switch must wait
five minutes before it can
restore the status of the primary
server to active.
timer quiet
minutes
Optional
Set the real-time accounting
interval
timer realtime-accounting
minutes
By default, the real-time
accounting interval is 12
minutes.
z
To control the interval at which users are charge in real time, you can set the real-time accounting
interval. After the setting, the switch periodically sends online users' accounting information to the
TACACS server at the set interval.
z
The real-time accounting interval must be a multiple of 3.
z
The setting of real-time accounting interval somewhat depends on the performance of the
TACACS client and server devices: A shorter interval requires higher device performance.