50
• Create a HWTACACS scheme, and specify the IP address of the authorization server and other
authorization parameters.
• Reference the created HWTACACS scheme in the ISP domain.
For more information, see the Security Configuration Guide.
When users adopt the scheme mode to log in to the device, the level of the commands that the users can
access depends on the user privilege level defined in the AAA scheme.
• When the AAA scheme is local, the user privilege level is defined by the authorization-attribute
level level command.
• When the AAA scheme is RADIUS or HWTACACS, the user privilege level is configured on the
RADIUS or HWTACACS server.
• For more information about AAA, RADIUS, and HWTACACS, see the Security Configuration
Guide.
Configuring the SSH client to log in to the SSH server
Configuration prerequisites
You have logged in to the device.
By default, you can log in to the device through the console port without authentication and have user
privilege level 3 after login. For information about logging in to the device with the default configuration,
see "Configuration requirements."
Figure 14 Log in to anot
her device from the current device
NOTE:
If the SSH client and the SSH server are not in the same subnet, make sure that the two devices can reach
each other.
Configuration procedure
Follow these steps to configure the SSH client to log in to the SSH server:
To do… Use the command…
Remarks
Log in to an IPv4 SSH server ssh2 server
Required
server is the IPv4 address or host
name of the server.
Available in user view
Log in to an IPv6 SSH server ssh2 ipv6 server
Required
server is the IPv6 address or host
name of the server.
Available in user view