Operation Manual - Security
Quidway S3000 Series Ethernet Switches
Chapter 2 AAA and RADIUS Protocol Configuration
2-6
Table 2-4
Set the method that a local user uses to set password
Operation Command
Set the method that a local user uses to set
password
local-user password-display-mode
{
cipher-force
|
auto
}
Cancel the method that the local user uses to
set password
undo local-user password-display-mode
Where,
auto
means that the password display mode will be the one specified by the
user at the time of configuring password (see the
password
command in the following
table for reference), and
cipher-force
means that the password display mode of all the
accessing users must be in cipher text.
Perform the following configurations in local user view.
Table 2-5
Set/Remove the attributes concerned with a specified user
Operation Command
Set a password for a specified
user
password
{
simple
|
cipher
}
password
Remove the password set for
the specified user
undo password
Set the state of the specified
user
state
{
active
|
block
}
Set a service type for the
specified user ( For S3026)
service-type
{
telnet
[
level
level
]
|
ftp
[
ftp-directory
directory
] |
lan-access
}
Cancel the service type of the
specified user ( For S3026)
undo service-type
{
telnet
[
level
]
|
ftp
[
ftp-directory
] |
lan-access
}
Set a service type for the
specified user ( Except
S3026)
service-type
{
ftp
[
ftp-directory
directory
] |
lan-access
|
ssh
[
level
level
|
telnet
[
level
level
]
] |
telnet
[
level
level
|
ssh
[
level
level
] ]
}
Cancel the service type of the
specified user ( Except
S3026)
undo service-type
{
ftp
[
ftp-directory
] |
lan-access
|
ssh
[
level
|
telnet
[
level
] ] |
telnet
[
level
|
ssh
[
level
] ]
}
Configure the attributes of
lan-access users
attribute
{
ip
ip-address
|
mac
mac-address
|
idle-cut
second
|
access-limit
max-user-number
|
vlan
vlanid
|
location
{
nas-ip
ip-address
port
portnum
|
port
portnum }
}*
Remove the attributes
defined for the lan-access
users
undo attribute
{
ip
|
mac
|
idle-cut
|
access-limit
|
vlan
|
location
}*
2.2.5 Disconnect a User by Force
Sometimes it is necessary to disconnect a user or a category of users by force. The
system provides the following command to serve for this purpose.
Perform the following configurations in system view.