Got it

MA5608T TACACS SSH Authentication Not Working

Created: Aug 7, 2020 10:40:01Latest reply: Aug 7, 2020 11:33:55 532 3 0 0 0
  Rewarded HiCoins: 0 (problem resolved)

Hello everyone.


I can't find the correct configuration to verify ssh/telnet login on Huawei SmartAX MA5608T.

According to the manual I have to authenticate against the tacacs server. it is not possible against the radius.

When you log in to an account that is not locally based, it is not even sent any packet if you authenticate to the tacacs server. 

Tested on different chassis with versions R015 and R018. the behavior is the same.

I am attaching the configuration settings.


VERSION : MA5600V800R018C10

PATCH   : SPC209

PRODUCT :MA5608T 



hwtacacs-server template "ma56t-login"

 hwtacacs-server authentication x.x.x.x (ip od tacacs server)

 hwtacacs-server authorization x.x.x.x (ip od tacacs server)

 hwtacacs-server accounting x.x.x.x (ip od tacacs server)

 hwtacacs-server source-ip y.y.y.y (ip of meth interface)

 hwtacacs-server shared-key "secret password"

 hwtacacs-server timer response-timeout 2

 undo hwtacacs-server user-name domain-included

#

[aaa]

  <aaa>

aaa

 authentication-scheme "default"

 authentication-scheme "login-auth"

  authentication-mode hwtacacs local

 #

 authorization-scheme "default"

 authorization-scheme "login-auth"

  authorization-mode hwtacacs local if-authenticated

  authorization-cmd 0 hwtacacs local

  authorization-cmd 1 hwtacacs local

  authorization-cmd 2 hwtacacs local

 #

 accounting-scheme "default"

 accounting-scheme "login-auth"

  accounting-mode hwtacacs

 #

 domain "default"

  authentication-scheme "login-auth"

  authorization-scheme "login-auth"

  accounting-scheme "login-auth"

  hwtacacs-server "ma56t-login"

 #

 user privilege level 2

 #

 recording-scheme "login-auth"

  recording-mode hwtacacs "ma56t-login"

 #

 cmd recording-scheme "login-auth"

 #


So is there a configuration error?

I did not find the answer in the manual or on other forums.

Thanks.

Featured Answers

Recommended answer

Chenxintao
Admin Created Aug 7, 2020 11:33:55

Hello, friend!



I Check your commands. The configuration commands are correct.


The user name must be followed by the domain name, for example, huawei@default.


The prerequisite is that the server can be pinged, run the ping -a source-ip server-ip command.


If the server can be pinged and the source IP address of the device has permission to access the server, the device is normal.


If the problem persists:


To solve your problem, I need to commission the interaction between the server and the NE. 


The commissioning commands are not public and are complex. You are advised to contact Huawei after-sales engineers for help.  


Huawei enterprise network technical support hotline: https://e.huawei.com/en/service-hotline-query


Thanks!

View more
  • x
  • convention:

jirkavaculik
jirkavaculik Created Aug 7, 2020 12:53:16 (0) (0)
Hello,
ping and comunication is not problem. firewall is ok.
about domain command "undo hwtacacs-server user-name domain-included" solved problem about domain.
And problem is not autentification but no comunication OLT and tacacs server.
a try technical support.
thanks.  
All Answers
Hello,
It's nice to meet you in the community.
We're working on your problem. Please wait patiently.
View more
  • x
  • convention:

Hello, friend!



I Check your commands. The configuration commands are correct.


The user name must be followed by the domain name, for example, huawei@default.


The prerequisite is that the server can be pinged, run the ping -a source-ip server-ip command.


If the server can be pinged and the source IP address of the device has permission to access the server, the device is normal.


If the problem persists:


To solve your problem, I need to commission the interaction between the server and the NE. 


The commissioning commands are not public and are complex. You are advised to contact Huawei after-sales engineers for help.  


Huawei enterprise network technical support hotline: https://e.huawei.com/en/service-hotline-query


Thanks!

View more
  • x
  • convention:

jirkavaculik
jirkavaculik Created Aug 7, 2020 12:53:16 (0) (0)
Hello,
ping and comunication is not problem. firewall is ok.
about domain command "undo hwtacacs-server user-name domain-included" solved problem about domain.
And problem is not autentification but no comunication OLT and tacacs server.
a try technical support.
thanks.  

Comment

You need to log in to comment to the post Login | Register
Comment

Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " User Agreement."

My Followers

Login and enjoy all the member benefits

Login

Block
Are you sure to block this user?
Users on your blacklist cannot comment on your post,cannot mention you, cannot send you private messages.
Reminder
Please bind your phone number to obtain invitation bonus.