Accounting-scheme-name : default
Authorization-scheme-name : -
Service-scheme-name : -
RADIUS-server-template : -
HWTACACS-server-template : -
<Huawei>
display authentication-scheme default
Authentication-scheme-name : default
Authentication-method : Local
Authentication-super method : Super authentication-super
<Huawei>
display authorization-scheme default
---------------------------------------------------------------------------
Authorization-scheme-name : default
Authorization-method : Local
......
<Huawei>
display accounting-scheme default
Accounting-scheme-name : default
Accounting-method : None
Create a local user whose user name contains the domain name. The Telnet user needs to
enter the domain name for authentication.
<Huawei>
system-view
[Huawei]
aaa
[Huawei-aaa]
local-user telnetuser@telnet password simple 123456
[Huawei-aaa]
local-user telnetuser@telnet service-type telnet
----End
Summary
Use different authentication modes for access users (such as 802.1x user), Telnet users, and
Secure Shell (SSH) users. When a Telnet user fails to log in to the AR2200-S, the possible cause
is that an incorrect authentication scheme is configured in the VTY user interface view and AAA
view of the AR2200-S, or on the remote authentication server.
10.2 ARP Security Troubleshooting
10.2.1 The ARP Entry of an Authorized User Is Maliciously
Modified
Common Causes
This fault is commonly caused by the following:
l
An attacker sends bogus ARP packets to modify the ARP entry of the authorized user.
Troubleshooting Flowchart
An authorized user is disconnected from the Internet, but the links and routes are normal. The
possible cause is that an attacker sends bogus ARP packets to modify the ARP entry of the user
on the gateway. As a result, this user is disconnected from the network.
Huawei AR2200-S Series Enterprise Routers
Troubleshooting
10 Security
Issue 01 (2012-01-06)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
284