iTable of Contents1 AAA Overview ············································································································································1-1Introduction to AAA ·································································································································1-1Authentication··································································································································1-1Authorization····································································································································1-2Accounting·······································································································································1-2Introduction to ISP Domain ·············································································································1-2Introduction to AAA Services ··················································································································1-3Introduction to RADIUS ···················································································································1-3Introduction to HWTACACS ············································································································1-72 AAA Configuration ····································································································································2-1AAA Configuration Task List ···················································································································2-1Configuration introduction ···············································································································2-1Creating an ISP Domain and Configuring Its Attributes ··································································2-2Configuring an AAA Scheme for an ISP Domain ············································································2-3Configuring Dynamic VLAN Assignment·························································································2-6Configuring the Attributes of a Local User·······················································································2-9Cutting Down User Connections Forcibly······················································································2-10RADIUS Configuration Task List···········································································································2-11Creating a RADIUS Scheme ·········································································································2-12Configuring RADIUS Authentication/Authorization Servers ··························································2-13Configuring Ignorance of Assigned RADIUS Authorization Attributes ··········································2-14Configuring RADIUS Accounting Servers ·····················································································2-15Configuring Shared Keys for RADIUS Messages ·········································································2-16Configuring the Maximum Number of RADIUS Request Transmission Attempts ············2-17Configuring the Type of RADIUS Servers to be Supported ··························································2-17Configuring the Status of RADIUS Servers···················································································2-18Configuring the Attributes of Data to be Sent to RADIUS Servers ···············································2-18Configuring the Local RADIUS Server ··························································································2-20Configuring Timers for RADIUS Servers·······················································································2-20Enabling Sending Trap Message when a RADIUS Server Goes Down ·······································2-21Enabling the User Re-Authentication at Restart Function·····························································2-22HWTACACS Configuration Task List····································································································2-23Creating a HWTACACS Scheme ··································································································2-23Configuring TACACS Authentication Servers ···············································································2-24Configuring TACACS Authorization Servers ·················································································2-24Configuring TACACS Accounting Servers ····················································································2-25Configuring Shared Keys for HWTACACS Messages ··································································2-26Configuring the Attributes of Data to be Sent to TACACS Servers ··············································2-26Configuring the Timers Regarding TACACS Servers ···································································2-27Displaying and Maintaining AAA Configuration ····················································································2-28