3Com Switch 8800 Configuration Guide Chapter 40 AAA and RADIUS/TACACS+ Protocol Con
figuration
40-34

III. Configuration procedure

Configure the Telnet user.
Here it is omitted.
Note:
The configuration of the FTP and Telnet users can refer to User Interface Configuration
of Getting Started Operation section of this manual.
Configure a TACACS+ scheme.
[SW8800] TACACS+ scheme hwtac
[SW8800-TACACS+-hwtac] primary authentication 10.110.91.164
[SW8800-TACACS+-hwtac] primary authorization 10.110.91.164
[SW8800-TACACS+-hwtac] key authentication expert
[SW8800-TACACS+-hwtac] key authorization expert
[SW8800-TACACS+-hwtac] user-name-format without-domain
[SW8800-TACACS+-hwtac] quit
Associate the domain with the TACACS+ scheme.
[SW8800] domain TACACS+
[SW8800-isp-TACACS+] scheme TACACS+-scheme hwtac
40.7 Troubleshooting AAA and RADIUS/TACACS+
RADIUS/TACACS+ protocol is located on the application layer of TCP/IP protocol suite.
It mainly specifies how to exchange user information between NAS and
RADIUS/TACACS+ server of ISP. So it is very likely to be invalid.

I. Symptom: User authentication/authorization always fails

Solution:
z The username may not be in the userid@isp-name format or NAS has not been
configured with a default ISP domain. Please use the username in proper format
and configure the default ISP domain on NAS.
z The user may have not been configured in the RADIUS/TACACS+ server
database. Check the database and make sure that the configuration information of
the user does exist in the database.
z The user may have input a wrong password. So please make sure that the
supplicant inputs the correct password.
z The encryption keys of RADIUS/TACACS+ server and NAS may be different.
Please check carefully and make sure that they are identical.