R21xx-HP FlexFabric 11900 Security Configuration Guide
209
SFTP client publickey authentication
configuration, 107
SSH client host public key configuration, 81
SSH password-publickey authentication, 78
SSH publickey authentication, 78
SSH user configuration, 82
Stelnet client publickey authentication
configuration, 103
Stelnet server publickey authentication
configuration, 94
QoS pre-classify
enabling (IPsec), 167
RADIUS
AAA configuration, 1, 16
AAA implementation, 2
AAA MPLS L3VPN implementation, 13
AAA scheme configuration, 18
accounting server parameter specification, 23
accounting-on feature configuration, 28
attributes, 13
authentication server specification, 22
client/server model, 2
common standard attributes, 13
differences between HWTACACS and RADIUS,
7
displaying, 29
extended attributes, 6
H3C proprietary attributes, 15
information exchange security mechanism, 2
maintaining, 29
max request transmission attempts, 25
outgoing packet source IP address, 26
packet exchange process, 3
packet format, 4
real-time accounting timer (realtime-accounting),
27
scheme configuration, 21
scheme creation, 22
scheme VPN specification, 24
security policy server IP address configuration,
29
server quiet timer (quiet), 27
server response timeout timer (response-timeout),
27
server SSH user authentication+authorization,
46
server status, 25
session-control feature configuration, 42
shared keys specification, 24
SSH user local authentication+HWTACACS
authorization+RADIUS accounting, 45
traffic statistics units, 24
troubleshooting, 54
troubleshooting accounting error, 55
troubleshooting authentication failure, 54
troubleshooting packet delivery failure, 54
user authentication mechanisms, 2
username format, 24
rate limit configuration, 125
real-time
HWTACACS real-time accounting timer, 34
RADIUS real-time accounting timer, 27
relay agent
authorized ARP (DHCP relay agent), 130
remote
AAA remote accounting method, 11
AAA remote authentication configuration, 16
AAA remote authentication method, 11
AAA remote authorization method, 11
Remote Authorization Dial-In User Service. Use
RADIUS
restricted forwarding configuration (ARP), 133
routing
SSH configuration, 77










