
30-11
Catalyst 4500 Series, Catalyst 2948G, Catalyst 2948G-GE-TX, and Catalyst 2980G Switches Software Configuration Guide—Release 8.2GLX
78-15908-01
Chapter 30 Configuring Switch Access Using AAA
Configuring Authentication
Setting the Authentication Login Attempts for Privileged Mode
To set the authentication login attempts for privileged mode, perform this task in privileged mode:
This example shows how to set the enable mode authentication login attempts to 5, set the enable mode
lockout time for both console and Telnet connections to 50 seconds, and verify the configuration:
Console> (enable) set authentication enable attempt 5
Enable mode authentication attempts for console and telnet logins set to 5.
Console> (enable) set authentication enable lockout 50
Enable mode lockout time for console and telnet logins set to 50.
Console> (enable) show authentication
Login Authentication: Console Session Telnet Session Http Session
--------------------- ---------------- ---------------- ----------------
tacacs disabled disabled disabled
radius disabled disabled disabled
kerberos disabled disabled disabled
local enabled(primary) enabled(primary) enabled(primary)
attempt limit 5 5 -
lockout timeout (sec) 50 50 -
Enable Authentication: Console Session Telnet Session Http Session
---------------------- ----------------- ---------------- ----------------
tacacs disabled disabled disabled
radius disabled disabled disabled
kerberos disabled disabled disabled
local enabled(primary) enabled(primary) enabled(primary)
attempt limit 5 5 -
lockout timeout (sec) 50 50 -
Console> (enable)
Task
Command
Step 1
Set the authentication login attempts for privileged
mode. Enter the console or telnet keywords if you want
to set the local authentication only for the console port or
for the Telnet connection attempts.
set authentication enable attempt {count}
[console | telnet]
Step 2
Set the login lockout time for privileged mode. Enter the
console or telnet keywords if you want to set the local
authentication only for the console port or for the Telnet
connection attempts.
set authentication enable lockout {time}
[console | telnet]
Step 3
Verify the local authentication configuration.
show authentication