![H3C SR8800-F Configuration Manual Download Page 33](http://html2.mh-extra.com/html/h3c/sr8800-f/sr8800-f_configuration-manual_4025863033.webp)
17
Step Command
Remarks
7.
(Optional.) Configure
authorization attributes
for the local user.
authorization-attribute
{
idle-cut
minutes
|
user-role
role-name
|
work-directory
directory-name
} *
The following default settings apply:
•
The working directory for FTP,
SFTP, and SCP users is the root
directory of the NAS. However, the
users do not have permission to
access the root directory.
•
The network-operator user role is
assigned to local users that are
created by a network-admin or
level-15 user.
8.
(Optional.) Configure
password control
attributes for the local
user.
•
Set the password aging
time:
password-control aging
aging-time
•
Set the minimum password
length:
password-control length
length
•
Configure the password
composition policy:
password-control
composition type-number
type-number
[
type-length
type-length
]
•
Configure the password
complexity checking policy:
password-control
complexity
{
same-character
|
user-name
}
check
•
Configure the maximum
login attempts and the
action to take if there is a
login failure:
password-control
login-attempt login-times
[
exceed
{
lock
|
lock-time
time
|
unlock
} ]
By default, the local user uses password
control attributes of the user group to
which the local user belongs.
9.
(Optional.) Assign the
local user to a user
group.
group
group-name
By default, a local user belongs to the
user group
system
.
Configuring attributes for network access users
When you configure attributes for a network access user, follow these restrictions and guidelines:
•
You can configure authorization attributes in local user view or user group view. The setting in
local user view takes precedence over the setting in user group view.
•
Configure the
location
binding attribute based on the service types of users.
{
For MAC authentication users, specify the MAC authentication-enabled Layer 2 Ethernet
interfaces through which the users access the device.
{
For portal users, specify the portal-enabled interfaces through which the users access the
device. Specify the Layer 2 Ethernet interfaces if portal is enabled on VLAN interfaces and
the
portal roaming enable
command is not configured.
To configure attributes for a network access user: