To do…

Use the command…

Remarks

 

 

 

Optional

 

 

 

By default, command

 

 

 

 

accounting is disabled. The

 

 

 

 

accounting server does not

 

 

 

 

record the commands executed

 

 

 

 

by users.

 

 

 

Command accounting allows

 

 

 

 

the HWTACACS server to

 

 

 

 

record all executed commands

 

 

 

 

that are supported by the

 

 

 

 

device, regardless of the

 

 

 

 

command execution result. This

 

 

 

 

helps control and monitor user

Enable command accounting

command accounting

 

operations on the device. If

 

command accounting is

 

 

 

 

 

 

 

 

enabled and command

 

 

 

 

authorization is not enabled,

 

 

 

 

every executed command is

 

 

 

 

recorded on the HWTACACS

 

 

 

 

server. If both command

 

 

 

 

accounting and command

 

 

 

 

authorization are enabled, only

 

 

 

 

the authorized and executed

 

 

 

 

commands are recorded on the

 

 

 

 

HWTACACS server.

 

 

 

Configure the AAA accounting

 

 

 

 

server before enabling

 

 

 

 

command accounting.

 

 

 

 

 

Exit to system view

quit

 

 

 

 

 

 

Enter the default ISP

domain domain-name

Optional

 

domain view

By default, the AAA scheme is

 

 

 

 

 

 

 

authentication default

local.

 

Specify the AAA

{ hwtacacs-scheme

If you specify the local AAA

 

scheme to be applied to hwtacacs-scheme-name[ local ]

scheme, perform the configuration

 

the domain

local none radius-scheme

concerning local user as well. If you

Configure

radius-scheme-name [ local ] }

specify an existing scheme by

the

 

 

providing the radius-scheme-name

 

 

authentic

 

argument, perform the following

ation

 

configuration as well:

mode

 

For RADIUS and HWTACACS

 

 

 

 

Exit to system view

quit

 

configuration, see the Security

 

 

Configuration Guide.

 

 

 

 

 

 

 

Configure the username and

 

 

 

 

password on the AAA server.

 

 

 

 

(For more information, see the

 

 

 

 

Security Configuration Guide.)

 

 

 

 

Create a local user and enter local

local-user user-name

By default, no local user exists.

user view

 

 

 

 

 

 

 

Set the local password

password { cipher simple }

Required

password

By default, no local password is set.

 

 

 

 

 

 

 

 

 

43