1-21
Configuring Local User Attributes
For local authentication, you need to create local users and configure user attributes on the device as
needed.
A local user represents a set of user attributes configured on a device and is uniquely identified by the
username. For a user requesting a network service to pass local authentication, you must add an entry
as required in the local user database of the device.
Each local user belongs to a local user group and bears all attributes of the group, such as the
authorization attributes. For details about local user group, refer to
Configuring User Group Attributes
.
You can configure an authorization attribute in user group view or local user view, making the attribute
effective on all local users of the group or only the local user. An authorization attribute configured in
local user view takes precedence over the same attribute configured in user group view.
Follow these steps to configure the attributes for a local user:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Set the password display mode for
all local users
local-user
password-display-mode
{
auto
|
cipher-force
}
Optional
auto
by default, indicating
to display the password of
a local user in the way
indicated by the
password
command.
Add a local user and enter local
user view
local-user user-name
Required
No local user exists by
default.
Configure a password for the local
user
password
{
cipher
|
simple
}
password
Optional
Place the local user to the state of
active or blocked
state
{
active
|
block
}
Optional
When created, a local user
is in the state of active by
default, and the user can
request network services.
Set the maximum number of user
connections using the local user
account
access-limit max-user-number
Optional
By default, there is no limit
on the maximum number of
user connections using the
same local user account.
Specify the service types for the
local user
service-type
{
ftp
|
lan-access
|
{
ssh
|
telnet
|
terminal
} * |
portal
}
Optional
By default, no service is
authorized to a local user.
Configure the binding attributes for
the local user
bind-attribute
{
call-number
call-number
[ :
subcall-number
] |
ip
ip-address
|
location
port
slot-number subslot-number
port-number
|
mac
mac-address
|
vlan vlan-id
} *
Optional
By default, no binding
attribute is configured for a
local user.
Summary of Contents for S7902E
Page 82: ...1 4 DeviceA interface tunnel 1 DeviceA Tunnel1 service loopback group 1 ...
Page 200: ...1 11 DeviceB display vlan dynamic No dynamic vlans exist ...
Page 598: ...ii ...
Page 1757: ...4 9 ...
Page 1770: ...6 4 ...
Page 2017: ...2 11 Figure 2 3 SFTP client interface ...
Page 2238: ...1 16 DeviceA cfd linktrace service instance 1 mep 1001 target mep 4002 ...