30-29
Cisco Security Appliance Command Line Configuration Guide
OL-12172-03
Chapter 30 Configuring Connection Profiles, Group Policies, and Users
Configuring Connection Profiles
Figure 30-2
Active Directory—User Must Change Password at Next Logon
The next time this user logs on, the security appliance displays the following prompt: “New password
required. Password change required. You must enter a new password with a minimum length
n
to
continue.” You can set the minimum required password length,
n
, as part of the Active Directory
configuration at Start > Programs > Administrative Tools > Domain Security Policy > Windows
Settings > Security Settings > Account Policies > Password Policy. Select Minimum password length.
Using Active Directory to Specify Maximum Password Age
To enhance security, you can specify that passwords expire after a certain number of days. To specify a
maximum password age for a user password, specify the
password-management
command in
tunnel-group general-attributes configuration mode on the security appliance and do the following steps
under Active Directory:
Step 1
Select Start > Programs > Administrative Tools > Domain Security Policy > Windows Settings >
Security Settings > Account Policies > Password Policy.
Step 2
Double-click Maximum password age. This opens the Security Policy Setting dialog box.
Step 3
Check the Define this policy setting check box and specify the maximum password age, in days, that you
want to allow.
Summary of Contents for 500 Series
Page 38: ...Contents xxxviii Cisco Security Appliance Command Line Configuration Guide OL 12172 03 ...
Page 45: ...P A R T 1 Getting Started and General Information ...
Page 46: ......
Page 277: ...P A R T 2 Configuring the Firewall ...
Page 278: ......
Page 561: ...P A R T 3 Configuring VPN ...
Page 562: ......
Page 891: ...P A R T 4 System Administration ...
Page 892: ......
Page 975: ...P A R T 5 Reference ...
Page 976: ......