Action
Command
Check the configuration of the HWTACACS
server template.
display hwtacacs-server template
Step 4
Check information about the HWTACACS packets sent and received by the AR2200-S.
Run the
debugging hwtacacs all
command in the user view to enable HWTACACS packet
debugging. Initiate HWTACACS authentication. Check whether any HWTACACS packets are
being sent or received by the AR2200-S.
<Huawei>
debugging hwtacacs all
<Huawei>
terminal debugging
<Huawei>
terminal monitor
CAUTION
Debugging affects the system performance. So, after debugging, run the
undo debugging all
command to disable the debugging immediately.
l
If no debugging information is displayed, the router configuration is incorrect. Check that
the HWTACACS server template is applied to the domain.
The following configuration file shows that the HWTACACS server template
hwtacacs
is
bound to the domain
huawei
.
#
hwtacacs-server template hwtacacs
hwtacacs-server authentication 2.2.2.2
#
aaa
authentication-scheme default
authentication-scheme aaa
authentication-mode hwtacacs
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
domain huawei
authentication-scheme aaa
hwtacacs-server hwtacacs
#
l
If debugging information is displayed, proceed according to the debugging information.
Huawei AR2200-S Series Enterprise Routers
Troubleshooting
10 Security
Issue 01 (2012-01-06)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
275