Generally, the access users are named in the userid@isp-nameor userid.isp-nameformat. Where, isp-nameafter the “@” or “.” character represents the ISP domain name. If the TACACS server does not accept the user names that carry ISP domain names, it is necessary to remove domain names from user names before they are sent to TACACS server.

Configuring the Timers Regarding TACACS Servers

Follow these steps to configure the timers regarding TACACS servers:

 

To do…

Use the command…

Remarks

 

 

Enter system view

system-view

 

 

 

 

 

 

 

Create a HWTACACS scheme

hwtacacs scheme

Required

 

 

By default, no HWTACACS

 

 

and enter its view

hwtacacs-scheme-name

 

 

scheme exists.

 

 

 

 

 

 

 

 

 

 

 

Set the response timeout time

timer response-timeout

Optional

 

 

By default, the response timeout

 

 

of TACACS servers

seconds

 

 

time is five seconds.

 

 

 

 

 

 

 

 

 

 

 

Set the time that the device

 

Optional

 

 

 

By default, the device must wait

 

 

must wait before it can restore

timer quiet minutes

 

 

five minutes before it can restore

 

 

the status of the primary server

 

 

 

the status of the primary server to

 

 

to active

 

 

 

 

active.

 

 

 

 

 

 

 

 

 

 

 

Set the real-time accounting

timer realtime-accounting

Optional

 

 

By default, the real-time

 

 

interval

minutes

 

 

accounting interval is 12 minutes.

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

zTo control the interval at which users are charge in real time, you can set the real-time accounting interval. After the setting, the device periodically sends online users' accounting information to the TACACS server at the set interval.

zThe real-time accounting interval must be a multiple of 3.

zThe setting of real-time accounting interval somewhat depends on the performance of the TACACS client and server devices: A shorter interval requires higher device performance.

2-24

Page 283
Image 283
3Com WX3000 operation manual Configuring the Timers Regarding Tacacs Servers, Scheme exists Set the response timeout time