< Home

Licensing Requirements and Limitations for AAA

Involved Network Elements

Table 1 Components involved in AAA networking

Role

Product Model

Description

AAA server

Huawei server or third-party AAA server

Performs authentication, accounting, and authorization for users.

Licensing Requirements

AAA is a basic feature of a switch and is not under license control.

Feature Support in V200R019C10

All models of S2720, S5700, and S6700 series switches support AAA.

For details about software mappings, visit Hardware Query Tool and search for the desired product model.

Feature Limitations

  • To prevent data transmission risks between the device and the RADIUS or HWTACACS server, you are advised to deploy the device and RADIUS or HWTACACS server in a security domain.
  • The authorization scheme and UCL group are not supported in the traditional NAC mode. The authorization user group is supported only in the traditional NAC mode.
  • If non-authentication is configured using the authentication-mode (authentication scheme view) command, users can pass the authentication using any user name or password. To protect the device and improve network security, you are advised to enable authentication to allow only authenticated users to access the device or network.
  • By default, the global default common domain default and global default management domain default_admin are bound to the accounting scheme default. Modifying the accounting scheme default affects configurations of the two domains. Exercise caution when modifying the accounting scheme to prevent user accounting failures.
  • After the NETCONF function is disabled, online HACA users will continue to be online, but new HACA users cannot go online.
  • When both DSCP priority mapping and 802.1p priority mapping are authorized for uplink packets, DSCP priority mapping takes effect on the S5720-HI, S5730-HI, S5731-H, S5731S-H, S5732-H, S5731-S, S5731S-S, S6720-HI, S6730-H, S6730S-H, S6730-S, and S6730S-S, and 802.1p priority mapping takes effect on the S5720-EI, S6720-EI, and S6720S-EI ,S5735-L, S5735S-L, S5735S-L-M, S5735-S, S5735S-S, and S5735-S-I regardless of the priority mapping mode trusted by interfaces.
Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
< Previous topic Next topic >