3-34
To do…
Use the command…
Remarks
Enable command authorization
command authorization
Optional
z
By default, command
authorization is not enabled.
z
By default, the command level
depends on the user privilege
level. A user is authorized a
command level not higher than
the user privilege level. With
command authorization enabled,
the command level for a login
user is determined by both the
user privilege level and AAA
authorization. If a user executes
a command of the corresponding
command level, the authorization
server checks whether the
command is authorized. If yes,
the command can be executed.
Enable command accounting
command accounting
Optional
z
By default, command accounting
is disabled. The accounting
server does not record the
commands executed by users.
z
Command accounting allows the
HWTACACS server to record all
the commands executed by
users, regardless of command
execution results. This helps
control and monitor user
operations on the device. If
command accounting is enabled
and command authorization is
not enabled, every executed
command is recorded on the
HWTACACS server. If both
command accounting and
command authorization are
enabled, only the authorized and
executed commands are
recorded on the HWTACACS
server.
Return to system view
quit
—
Enter the ISP
domain view
domain
domain-name
Apply the specified
AAA scheme to
the domain
authentication default
{
hwtacacs-scheme
hwtacacs-scheme-name
[
local
] |
local
|
none
|
radius-scheme
radius-scheme-name
[
local
] }
Configure
the
authentic
ation
mode
Exit to system
view
quit
Optional
By default, the AAA scheme is
local
.
If you specify the local AAA scheme,
you need to perform local user
configuration. If you specify an
existing scheme by providing the
radius
-
scheme-name
argument,
perform the following configuration
as well:
z
For RADIUS and HWTACACS
configuration, see
AAA
in the
Security Configuration Guide
.
z
Configure the username and
password accordingly on the
AAA server. (For more
information, see
AAA
in the
Security Configuration Guide
.)
Create a local user and enter
local user view
local-user user-name
Required
By default, no local user exists.
Summary of Contents for SR6600 SPE-FWM
Page 112: ...6 101...