Got it

USG6655E HWTACACS authentication issue

Created: Jul 14, 2021 14:42:21Latest reply: Jul 31, 2021 02:49:18 480 6 1 0 0
  Rewarded HiCoins: 0 (problem resolved)

I configured HWTACACS on USG6655E, i created huawei domain but there is no command to change it to default domain, I read a post here that we have to use default domain for HWTACACS, I am sharing my proposed configuration, can anyone check it. is it ok or need to modify?  Thanks


hwtacacs-server template hwtacacs

 hwtacacs-server authentication 10.10.10.10

 hwtacacs-server authorization 10.10.10.10

 hwtacacs-server accounting 10.10.10.10

 hwtacacs-server shared-key cipher abc123

 undo hwtacacs-server user-name domain-included



domain default

  authentication-scheme hwtacacs

  accounting-scheme hwtacacs

  authorization-scheme hwtacacs

  hwtacacs-server hwtacacs

  service-type administrator-access

  internet-access mode password

  reference user current-domain



 manager-user adminadmin

  password cipher abc123

  service-type web terminal ssh

  level 15

  authentication-scheme hwtacacs

  authorization-scheme hwtacacs

  hwtacacs-server hwtacacs


        OR


 manager-user nadeem

  password cipher abc123

  service-type web terminal ssh

  level 15

  authentication-scheme admin_hwtacacs_local

  hwtacacs-server hwtacacs



  • x
  • convention:

Featured Answers
DDSN
Admin Created Jul 14, 2021 15:24:31

Hi nadeemkhawar279,
The ‘default’ domain in your configuration is the default domain that exists on the device.
You can refer to https://support.huawei.com/hedex/hdx.do?docid=EDOC1100122846&id=EN-US_CLIREF_0176366681&lang=en
View more
  • x
  • convention:

nadeemkhawar279
nadeemkhawar279 Created Jul 15, 2021 08:17:26 (0) (0)
Yes i am using default domain because I didn't find any command on firewall to change new domain to use as default domain. We can chose any domain in CE switches as default domain but not in firewalls USG6655.  
DDSN
DDSN Reply nadeemkhawar279  Created Jul 16, 2021 08:30:06 (0) (0)
Hi,
According to experts, the USG6655 does not support changing the default domain.  
All Answers
BetterMing
BetterMing Created Jul 14, 2021 14:43:27

Hello, dear.
It's nice to meet you in the community.
We're working on getting the right answer for you. Please rest assured that we'll be back with an answer shortly.
View more
  • x
  • convention:

DDSN
DDSN Admin Created Jul 14, 2021 15:24:31

Hi nadeemkhawar279,
The ‘default’ domain in your configuration is the default domain that exists on the device.
You can refer to https://support.huawei.com/hedex/hdx.do?docid=EDOC1100122846&id=EN-US_CLIREF_0176366681&lang=en
View more
  • x
  • convention:

nadeemkhawar279
nadeemkhawar279 Created Jul 15, 2021 08:17:26 (0) (0)
Yes i am using default domain because I didn't find any command on firewall to change new domain to use as default domain. We can chose any domain in CE switches as default domain but not in firewalls USG6655.  
DDSN
DDSN Reply nadeemkhawar279  Created Jul 16, 2021 08:30:06 (0) (0)
Hi,
According to experts, the USG6655 does not support changing the default domain.  
LilStylz237
LilStylz237 Created Jul 22, 2021 21:03:33

Very great
View more
  • x
  • convention:

chenhui
chenhui Admin Created Jul 31, 2021 02:49:18

Hi,
Does the answer fit your question? Your valuable feedback would help our improvement.
View more
  • x
  • convention:

Comment

You need to log in to comment to the post Login | Register
Comment

Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " User Agreement."

My Followers

Login and enjoy all the member benefits

Login

Block
Are you sure to block this user?
Users on your blacklist cannot comment on your post,cannot mention you, cannot send you private messages.
Reminder
Please bind your phone number to obtain invitation bonus.