7
Step Command
Remarks
{
cipher
|
simple
}
password
5.
Configure common settings
for console login.
See "
user interface settings (optional)
Optional.
The next time you attempt to log in through the console port, you must provide the configured login
password.
Configuring scheme authentication for console login
When scheme authentication is used, you can choose to configure the command authorization and
command accounting functions.
If command authorization is enabled, a command is available only if the user has the commensurate user
privilege level and is authorized to use the command by the AAA scheme.
Command accounting allows the HWTACACS server to record all commands executed by users,
regardless of command execution results. This function helps control and monitor user behaviors on the
device. If command accounting is enabled and command authorization is not enabled, every executed
command is recorded on the HWTACACS server. If both command accounting and command
authorization are enabled, only the authorized and executed commands are recorded on the
HWTACACS server.
Follow these guidelines when you configure scheme authentication for console login:
•
To make the command authorization or command accounting function take effect, apply an
HWTACACS scheme to the intended ISP domain. This scheme must specify the IP address of the
authorization server and other authorization parameters.
•
If the local authentication scheme is used, use the
authorization-attribute level
level command in
local user view to set the user privilege level on the device.
•
If a RADIUS or HWTACACS authentication scheme is used, set the user privilege level on the
RADIUS or HWTACACS server.
To configure scheme authentication for console login:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter console user interface
view.
user-interface console
first
-
number
[
last-number
]
N/A
3.
Enable scheme
authentication.
authentication-mode
scheme
Whether local, RADIUS, or
HWTACACS authentication is
adopted depends on the configured
AAA scheme.
By default, console login users are
not authenticated.
4.
Enable command
authorization.
command authorization
Optional.
By default, command authorization
is disabled. The commands
available for a user only depend on
the user privilege level.