R3166-R3206-HP High-End Firewalls Access Control Configuration Guide-6PW101

iv
Configuring local users ······································································································································· 127
Configuring RADIUS schemes in the web interface ························································································· 131
RADIUS configuration example in the web interface ······················································································ 135
Configuring RADIUS schemes in the CLI ··········································································································· 136
Configuring HWTACACS schemes in the web interface ················································································ 147
HWTACACS configuration example in the web interface ············································································· 151
Configuring HWTACACS schemes in the CLI ·································································································· 152
Configuring AAA methods for ISP domains ·············································································································· 158
Configuration prerequisites ································································································································ 158
Creating an ISP domain ····································································································································· 158
Configuring ISP domain attributes ····················································································································· 159
Configuring AAA authentication methods for an ISP domain ········································································ 160
Configuring AAA authorization methods for an ISP domain ········································································· 161
Configuring AAA accounting methods for an ISP domain ············································································· 163
Tearing down user connections ·································································································································· 164
Configuring a NAS ID-VLAN binding ························································································································ 165
Displaying and maintaining AAA ······························································································································ 165
AAA configuration examples ······································································································································ 166
Authentication/authorization for Telnet/SSH users by a RADIUS server ······················································ 166
Local authentication/authorization for Telnet/FTP users ················································································· 169
RADIUS authentication and authorization for Telnet users by a network device ········································· 170
Troubleshooting AAA ·················································································································································· 172
Troubleshooting RADIUS ····································································································································· 172
Troubleshooting HWTACACS ···························································································································· 174
Configuration guidelines ············································································································································· 174
Configure the RADIUS client note the following guidelines ············································································ 174
Configuring the HWTACACS client note the following guidelines ································································ 174
Support and other resources ·································································································································· 175
Contacting HP ······························································································································································ 175
Subscription service ············································································································································ 175
Related information ······················································································································································ 175
Documents ···························································································································································· 175
Websites ······························································································································································· 175
Conventions ·································································································································································· 176
Index ········································································································································································ 178