Password Control Configuration
293
When the maximum attempt times is exceeded, the system operates in one of the
following procession mode:
■
locktime: in this mode, the system inhibit the user from re-login within a
certain time period. After that period of time, the user is allowed to log in the
switch again. By default, this time is 120 minutes.
■
lock: in this mode, the system inhibit the user from re-login forever. The user is
allowed to log in the switch again only after the administrator removes the user
from the user blacklist.
■
unlock: in this mode, the system allows the user to log in again.
CAUTION:
No inhibition operation is performed for the users who execute the
super command but fail the password attempts.
CAUTION:
If a user in the blacklist changes his/her IP address, the blacklist will not
affect the user anymore when the user logs in the switch.
The system administrator can perform the following operations to manually
remove one or all user entries in the blacklist.
Configuring the Timeout
for User Password
Authentication
The authentication procedure starts from the time the local/remote server of the
switch receives the user name and ends at the time the user authentication is
completed. Whether the user is authenticated on the local server or on a remote
server is determined by the related AAA configuration. For more details, see the
secure module of this guide.
If a password authentication is not completed within the configured
authentication timeout time, the authentication fails, and the system terminates
the connection of the user and makes some logging.
Display the information about
one or all users added in the
blacklist
display
password-control
blacklist [
username username |
ipaddress
ip-address ]
You can execute the display
command in any view
Table 342
Remove User Entries in Blacklist
Operation
Command
Description
Enter system view
system-view
Delete one specific or all user
entries in the blacklist
reset
password-control
blacklist [
username username ]
Executing this command without
the username username option
will remove all the user entries in
the blacklist.
Executing this command with the
username username option will
remove the specified user entry
in the blacklist.
Table 341
Configure Login Attempts Limitation and Failure Procession Mode
Operation
Command
Description
Содержание 400 Family
Страница 12: ......
Страница 16: ...14 ABOUT THIS GUIDE ...
Страница 58: ...56 CHAPTER 2 PORT OPERATION ...
Страница 68: ...66 CHAPTER 3 VLAN OPERATION ...
Страница 98: ...96 CHAPTER 5 NETWORK PROTOCOL OPERATION ...
Страница 124: ...122 CHAPTER 6 IP ROUTING PROTOCOL OPERATION ...
Страница 156: ...154 CHAPTER 8 ACL CONFIGURATION ...
Страница 218: ...216 CHAPTER 11 802 1X CONFIGURATION ...
Страница 298: ...296 CHAPTER 13 PASSWORD CONTROL CONFIGURATION OPERATIONS ...
Страница 336: ...334 APPENDIX B RADIUS SERVER AND RADIUS CLIENT SETUP ...