Chapter 29 Object
USG20(W)-VPN Series User’s Guide
464
User Type
These are the kinds of user account the USG supports.
•
admin
- this user can look at and change the configuration of the USG
•
limited-admin
- this user can look at the configuration of the USG but
not to change it
•
user
- this user has access to the USG’s services but cannot look at the
configuration
•
guest
- this user has access to the
USG
’s services but cannot look at the
configuration
•
ext-user
- this user account is maintained in a remote server, such as
RADIUS or LDAP. See
for more
information about this type.
•
ext-group-user
- this user account is maintained in a remote server,
such as RADIUS or LDAP. See
Ext-Group-User Accounts on page 457
for
more information about this type.
Lease Time
This is the default lease time in minutes for each type of user account. It
defines the number of minutes the user has to renew the current session
before the user is logged out.
Admin users renew the session every time the main screen refreshes in the
Web Configurator. Access users can renew the session by clicking the
Renew
button on their screen. If you allow access users to renew time
), the users can select this
check box on their screen as well. In this case, the session is automatically
renewed before the lease time expires.
Reauthentication Time
This is the default reauthentication time in minutes for each type of user
account. It defines the number of minutes the user can be logged into the
USG in one session before having to log in again. Unlike
Lease Time
, the
user has no opportunity to renew the session without logging out.
Miscellaneous Settings
Allow renewing lease time
automatically
Select this check box if access users can renew lease time automatically, as
well as manually, simply by selecting the
Updating lease time
automatically
check box on their screen.
Enable user idle detection
This is applicable for access users.
Select this check box if you want the USG to monitor how long each access
user is logged in and idle (in other words, there is no traffic for this access
user). The USG automatically logs out the access user once the
User idle
timeout
has been reached.
User idle timeout
This is applicable for access users.
This field is effective when
Enable user idle detection
is checked. Type the
number of minutes each access user can be logged in and idle before the
USG automatically logs out the access user.
User Logon Settings
Limit the number of
simultaneous logons for
administration account
Select this check box if you want to set a limit on the number of
simultaneous logins by admin users. If you do not select this, admin users
can login as many times as they want at the same time using the same or
different IP addresses.
Maximum number per
administration account
This field is effective when
Limit ... for administration account
is
checked. Type the maximum number of simultaneous logins by each admin
user.
Limit the number of
simultaneous logons for
access account
Select this check box if you want to set a limit on the number of
simultaneous logins by non-admin users. If you do not select this, access
users can login as many times as they want as long as they use different IP
addresses.
Maximum number per
access account
This field is effective when
Limit ... for access account
is checked. Type
the maximum number of simultaneous logins by each access user.
Table 183
Configuration > Object > User/Group > Setting (continued)
LABEL
DESCRIPTION
Summary of Contents for ZyWall USG20-VPN
Page 17: ...17 PART I User s Guide ...
Page 18: ...18 ...
Page 99: ...99 PART II Technical Reference ...
Page 100: ...100 ...