Got it

OLT hwtacacs issue with domain name

Created: Sep 13, 2021 08:36:10Latest reply: Oct 15, 2021 07:19:27 314 10 0 0 0
  Rewarded HiCoins: 5 (problem resolved)

I cannot login OLT with domain name. such as a@xyz.com.tr With same way I can login Router and switch 


OLT version EA5800-X17 version is not important because All version has same command like

hwtacacs server template x

hwtacacs server user name domain included. 


Please help

Featured Answers

Best answer

Recommended answer

Nino_Chou
Admin Created Sep 13, 2021 09:56:29

Posted by fargat at 2021-09-13 09:23 My config: terminal user authentication mode localAdding this command “hwtacacs-server user-name do ...

Hi friend.


Depending on the configuration you provide, 

  1. Note that your configuration mode is local. Since you are performing authentication on the HWTACACS, you can try to change the configuration mode to the server.

  2. You can log in to the router and switch using your domain name. Therefore, check whether the configurations of the OLT are different from those of the router and switch. Generally, the configurations should be the same.

 If the fault persists, check whether the fault is caused by the third-party server. 


 Thank you!

View more
  • x
  • convention:

fargat
fargat Created Sep 13, 2021 10:40:03 (0) (0)
Configuration is same with Switch  
All Answers
Hello, friend!
It's nice to meet you in the community.
We're working on getting the right answer for you.
View more
  • x
  • convention:

Hi friend.


Did the HWTACACS server reject usernames containing domain names?

If yes, you can configure the user name of the HWTACACS server to exclude the domain name and send the user name to the HWTACACS server.


Example:

To configure a user name not to contain the domain name, do as follows:

huawei(config-hwtacacs-test1)#undo hwtacacs-server user-name domain-included


Thanks.

View more
  • x
  • convention:

fargat
fargat Created Sep 13, 2021 09:26:17 (0) (0)
This is not solution. Our customer wants to login with domain name .  
My config:

terminal user authentication mode local
Adding this command “hwtacacs-server user-name domain-included” under the HWTACACS server template.

aaa
domain name1
authentication-scheme xx
authorization-scheme xx
hwtacacs-server x
domain name2
authentication-scheme xx
authorization-scheme xx
hwtacacs-server x

user offline reason: username or password is wrong
View more
  • x
  • convention:

Posted by fargat at 2021-09-13 09:23 My config: terminal user authentication mode localAdding this command “hwtacacs-server user-name do ...

Hi friend.


Depending on the configuration you provide, 

  1. Note that your configuration mode is local. Since you are performing authentication on the HWTACACS, you can try to change the configuration mode to the server.

  2. You can log in to the router and switch using your domain name. Therefore, check whether the configurations of the OLT are different from those of the router and switch. Generally, the configurations should be the same.

 If the fault persists, check whether the fault is caused by the third-party server. 


 Thank you!

View more
  • x
  • convention:

fargat
fargat Created Sep 13, 2021 10:40:03 (0) (0)
Configuration is same with Switch  
Posted by Nino_Chou at 2021-09-13 09:56 Hi friend.Depending on the configuration you provide, Note that your configuration mode is local. ...
Fargat forgot to mention that he configured command “terminal user authentication mode AAA domain", I think this command is not necessary, but we do not know how to delete it.
View more
  • x
  • convention:

Nino_Chou
Nino_Chou Created Sep 13, 2021 14:08:38 (0) (0)
For details, see: https://support.huawei.com/hedex/hdx.do?docid=EDOC1100182924&id=EN-US_TASK_0254730899&lang=en  
it is solved. Problem is tacacs configuration about adding device
View more
  • x
  • convention:

Chenxintao
Chenxintao Created Oct 15, 2021 08:10:16 (0) (0)
 

Comment

You need to log in to comment to the post Login | Register
Comment

Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " User Agreement."

My Followers

Login and enjoy all the member benefits

Login

Block
Are you sure to block this user?
Users on your blacklist cannot comment on your post,cannot mention you, cannot send you private messages.
Reminder
Please bind your phone number to obtain invitation bonus.