R211x-HP Flexfabric 11900 Security Command Reference

Table Of Contents
65
Field Descri
p
tion
Realtime Accounting Interval(minutes)
Real-time accounting interval, in minutes.
Response Timeout Interval(seconds) HWTACACS server response timeout period, in seconds.
Username Format
Format for the usernames sent to the HWTACACS server. Possible
values include:
with-domain—Includes the domain name.
without-domain—Excludes the domain name.
keep-original—Forwards the username as it is entered.
Related commands
reset hwtacacs statistics
hwtacacs nas-ip
Use hwtacacs nas-ip to specify a source IP address for outgoing HWTACACS packets.
Use undo hwtacacs nas-ip to delete a source IP address for outgoing HWTACACS packets.
Syntax
hwtacacs nas-ip { ipv4-address | ipv6 ipv6-address } [ vpn-instance vpn-instance-name ]
undo hwtacacs nas-ip { ipv4-address | ipv6 ipv6-address } [ vpn-instance vpn-instance-name ]
Default
The source IP address of a packet sent to the server is the IP address of the outbound interface.
Views
System view
Predefined user roles
network-admin
mdc-admin
Parameters
ipv4-address: Specifies an IPv4 address, which must be an address of the device and cannot be 0.0.0.0,
255.255.255.255, a class D address, a class E address, or a loopback address.
ipv6 ipv6-address: Specifies an IPv6 address, which must be a unicast address of the device and cannot
be a loopback address or a link-local address.
vpn-instance vpn-instance-name: Specifies the MPLS L3VPN to which the source IP address belongs,
where vpn-instance-name is a case-sensitive string of 1 to 31 characters. To configure a public-network
source IPv4 address, do not specify this option.
Usage guidelines
The source IP address of HWTACACS packets that a NAS sends must match the IP address of the NAS
that is configured on the HWTACACS server. An HWTACACS server identifies a NAS by IP address.
Upon receiving an HWTACACS packet, an HWTACACS server checks whether the source IP address of
the packet is the IP address of a managed NAS. If it is, the server processes the packet. If it is not, the
server drops the packet.
You can specify up to 16 source IP addresses, including the following: