当前位置:网站首页>Configure the user to log in to the device through telnet -- AAA local authentication
Configure the user to log in to the device through telnet -- AAA local authentication
2022-06-30 05:52:00 【Pie Daxing's good friend Dingdang cat】
List of articles
AAA Local certification
AAA Local authentication can authenticate the identity of users , The user can successfully log in to the device by entering the correct user name and password .
- advantage :AAA Local authentication configures user information on the device , There is no need to deploy other authentication servers in the network , Faster and lower operating costs .
- shortcoming : The amount of information stored is limited by the hardware conditions of the device .
Networking requirements
As shown in the figure below , Enterprises hope that administrators can easily and safely manage devices remotely , The administrator can be configured to pass telnet When logging in to the device :
- The administrator can enter the correct user name and password to pass telnet Log in to the device .
- Administrator through telnet After logging in to the device , The command level that can be executed is 0~3 All command lines for .

Huawei switch configuration
Configuration ideas
- Can make telnet service .
- Configure the user through telnet The login authentication method is AAA.
- To configure AAA Local certification : Create local users 、 The access type of the specified user is telnet、 Configure the user level as 15 level .
Configuration topology

Configuration operation
- LSW1 Configure the interface and IP Address
<Huawei>sys
[Huawei]sysname HW1
[HW1]vlan batch 10
Info: This operation may take a few seconds. Please wait for a moment...done.
[HW1]int Vlanif 10
[HW1-Vlanif10]ip add 10.1.1.1 24
[HW1-Vlanif10]q
[HW1]int GigabitEthernet 0/0/1
[HW1-GigabitEthernet0/0/1]port link-type access
[HW1-GigabitEthernet0/0/1]port default vlan 10
[HW1-GigabitEthernet0/0/1]q
- Can make telnet Server function
[HW1]telnet server enable
Info: The Telnet server has been enabled.
- To configure vty The authentication method of the user interface is AAA
[HW1]user-interface maximum-vty 15
[HW1-ui-vty0-14]authentication-mode aaa
[HW1-ui-vty0-14]protocol inbound telnet
[HW1-ui-vty0-14]q
- To configure AAA Local certification
[HW1]aaa
[HW1-aaa]local-user user1 password cipher [email protected]
[HW1-aaa]local-user user1 service-type telnet
[HW1-aaa]local-user user1 privilege level 15
[HW1-aaa]q
- LSW2 Interface configuration
<Huawei>sys
Enter system view, return user view with Ctrl+Z.
[Huawei]sysname HW2
[HW2]vlan batch 10
[HW2]int Vlanif 10
[HW2-Vlanif10]ip add 10.1.1.2
[HW2-Vlanif10]q
[HW2]int GigabitEthernet 0/0/1
[HW2-GigabitEthernet0/0/1]port link-type access
[HW2-GigabitEthernet0/0/1]port default vlan 10
[HW2-GigabitEthernet0/0/1]q
- verification ,LSW2 telnet LSW1
<HW2>telnet 10.1.1.1
Trying 10.1.1.1 ...
Press CTRL+K to abort
Connected to 10.1.1.1 ...
Login authentication
Username:user1
Password:
Info: The max number of VTY users is 15, and the number
of current VTY users on line is 1.
The current login time is 2021-08-24 13:22:59.
<HW1>
The configuration file
LSW1 To configure
[HW1]dis cu
#
sysname HW1
#
vlan batch 10
#
cluster enable
ntdp enable
ndp enable
#
drop illegal-mac alarm
#
diffserv domain default
#
drop-profile default
#
aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user admin password simple admin
local-user admin service-type http
local-user user1 password cipher [JD(UTW1T15NZPO3JBXBHA!!
local-user user1 privilege level 15
local-user user1 service-type telnet
#
interface Vlanif1
#
interface Vlanif10
ip address 10.1.1.1 255.255.255.0
#
interface MEth0/0/1
#
interface GigabitEthernet0/0/1
port link-type access
port default vlan 10
#
user-interface maximum-vty 15
user-interface con 0
user-interface vty 0 14
authentication-mode aaa
#
return
LSW2 To configure
[HW2]dis cur
#
sysname HW2
#
vlan batch 10
#
cluster enable
ntdp enable
ndp enable
#
drop illegal-mac alarm
#
diffserv domain default
#
drop-profile default
#
aaa
authentication-scheme default
authorization-scheme default
accounting-scheme default
domain default
domain default_admin
local-user admin password simple admin
local-user admin service-type http
#
interface Vlanif1
#
interface Vlanif10
ip address 10.1.1.2 255.255.255.0
#
interface MEth0/0/1
#
interface GigabitEthernet0/0/1
port link-type access
port default vlan 10
#
return
边栏推荐
- 动态规划--怪盗基德的滑翔翼
- After reading who moved my cheese
- 1380. lucky numbers in matrices
- Codeforces C. Andrew and Stones
- [chestnut sugar GIS] global mapper - how to assign the elevation value of the grid to the point
- Cisco VXLAN配置
- What do you think of the deleted chat records? How to restore the deleted chat records on wechat?
- Leetcode56. consolidation interval
- [deep learning] data segmentation
- inno setup 最简单的自定义界面效果
猜你喜欢

Database SQL language 03 sorting and paging

At the age of 32, I fell into a middle-aged crisis and finally quit naked...

What kind of answer has Inspur given in the big AI model landing test?

Today, Ali came out with 35K. It's really sandpaper that wiped my ass. it showed me my hand

Sword finger offer 18 Delete the node of the linked list

Sword finger offer 22 The penultimate node in the linked list

14x1.5cm vertical label is a little difficult, VFP calls bartender to print

旋转框目标检测mmrotate v0.3.1 训练DOTA数据集(二)

Transfer the token on the matic-erc20 network to the matic polygon

Xctf attack and defense world crypto advanced area
随机推荐
MySQL存储系统
Did you know that WPS can turn on eye protection mode?
What are membrane stress and membrane strain
Lantern Festival | maoqiu technology and everyone "guess riddles and have a good night"
Sound network, standing in the "soil" of the Internet of things
inno setup 最简单的自定义界面效果
leetcode763. Divide letter interval
Ultra simple STM32 RTC alarm clock configuration
Stack overflow caused by C # using protobuf stack overflow
SSL证书续费相关问题详解
Xi'an Jiaotong automation control theory test simulation question [standard answer]
Learning about functions QAQ
Summary of redis learning notes (I)
English grammar_ Adjective / adverb Level 3 - superlative
Force deduction exercise -- deleting repeated items in ordered sequence 1.0
El table lazy load refresh
Xijiao 21 autumn "motor and drive" online homework answer sheet (I) [standard answer]
动态规划--怪盗基德的滑翔翼
炒股用指南针开户交易安全吗?
D. Big Brush