No relevant resource is found in the selected language.

This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies. Read our privacy policy>Search


To have a better experience, please upgrade your IE browser.


CX11x, CX31x, CX710 (Earlier Than V6.03), and CX91x Series Switch Modules V100R001C10 Configuration Guide 13

The documents describe the configuration of various services supported by the CX11x&CX31x&CX91x series switch modules The description covers configuration examples and function configurations.
Rate and give feedback:
Huawei uses machine translation combined with human proofreading to translate this document to different languages in order to help you better understand the content of this document. Note: Even the most advanced machine translation cannot match the quality of professional translators. Huawei shall not bear any responsibility for translation accuracy and it is recommended that you refer to the English document (a link for which has been provided).
AAA Configuration Tasks

AAA Configuration Tasks

After AAA configuration is complete, the device authenticates users and authorizes users to use particular services. In addition, the device also records the network resource usage of the user.

The device supports the combination of local, Remote Authentication Dial In User Service (RADIUS), and Huawei Terminal Access Controller Access Control System (HWTACACS) authentication, authorization, and accounting. For example, the device provides local authentication, local authorization, and RADIUS accounting.

In practice, as shown in Table 12-13, the following schemes are used separately. Multiple authentication or authorization modes can be used in a scheme. For example, local authentication is used as a backup of RADIUS authentication and HWTACACS authentication, and local authorization is used as a backup of HWTACACS authorization.

Table 12-13 AAA configuration tasks

Configuration Task



Local authentication and authorization

If users need to be authenticated or authorized but no RADIUS server or HWTACACS server is deployed on the network, use local authentication and authorization. Local authentication and authorization feature fast processing and low operation cost, whereas the amount of information that can be stored is limited by the device hardware capacity.

Local authentication and authorization are often used for administrators.

Configuring Local Authentication and Authorization

RADIUS authentication, authorization, and accounting

RADIUS protects a network from unauthorized access, which is often used on the networks demanding high security and remote user access control.

Configuring RADIUS AAA

HWTACACS authentication, authorization, and accounting

HWTACACS protects a network from unauthorized access and supports command-line authorization. Compared with RADIUS, HWTACACS is more reliable in transmission and encryption, and is more suitable for security control.

Configuring HWTACACS AAA

Updated: 2019-12-13

Document ID: EDOC1000041694

Views: 60288

Downloads: 3623

Average rating:
This Document Applies to these Products
Related Version
Related Documents
Previous Next