< Home

HWTACACS User Management

Overview

HWTACACS is an enhanced version of TACACS+. Similar to RADIUS, HWTACACS uses the client/server model for communication between the HWTACACS client and server to provide AAA functions (mainly for login users).

HWTACACS is more reliable than RADIUS, because HWTACACS runs atop TCP while RADIUS runs atop UDP.

In addition to encrypting the standard packet header, HWTACACS encrypts the entire packet body. Moreover, HWTACACS supports the configuration of a shared key for packet encryption, improving transmission security. For security purposes, it is recommended that the shared key contain at least 6 characters from at least two of the following categories: uppercase letters, lowercase letters, digits, and special characters. You are advised to periodically change the shared key.

Impact on the System

None

Procedure

  1. Enter the system view.

    system-view

  2. Create an HWTACACS server template and enter its view.

    hwtacacs-server template template-name

  3. Configure a shared key for the HWTACACS server.

    hwtacacs-server shared-key cipher key-string

Checking the Security Hardening Result

After a shared key is configured for the HWTACACS server on the device, it is displayed in ciphertext, and users cannot obtain its information.

Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
< Previous topic Next topic >