
Password Control Configuration
557
■
“Configuring History Password Recording”
■
“Configuring a User Login Password in Interactive Mode”
■
“Configuring Login Attempt Times Limitation and Failure Processing Mode”
■
“Configuring the Password Authentication Timeout Time”
■
“Configuring Password Composition Policies”
After the above configuration, you can execute the
display password-control
command in any view to check the information about the password control for all
users, including the enabled/disabled state of password aging, the aging time,
enabled/disabled state of password composition policy, minimum number of types
that a password should contain, minimum number of characters of each type, the
enabled/disabled state of history password recording, the maximum number of
history password records, the alert time before password expiration, the timeout
time for password authentication, the maximum number of attempts, and the
processing mode for login attempt failures.
If the password attempts of a user fail for several times, the system adds the user
to the blacklist. You can execute the
display password-control blacklist
command in any view to check the names and the IP addresses of such users.
Configuring Password
Aging
n
In this section, you must note the effective range of the same commands when
executed in different views or to different types of passwords:
■
Global settings in system view apply to all local user passwords and super
passwords.
Table 409
Configure password aging
Operation
Command
Description
Enter system view
system-view
-
Enable password aging
password-control aging enable
Optional
By default, password aging is
enabled.
Configure a password
aging time globally
password-control aging
aging-time
Optional
By default, the aging time is
90 days.
Configure a password
aging time for a super
password
password-control super aging
aging-time
Optional
By default, the aging time is
90 days.
Enable the system to alert
users to change their
passwords when their
passwords will soon expire,
and specify how many
days ahead of the
expiration the system alerts
the users.
password-control
alert-before-expire
alert-time
Optional
By default, users are alerted
seven days ahead of the
password expiration.
Create a local user or enter
local user view
local-user
user-name
-
Configure a password
aging time for the local
user
password-control aging
aging-time
Optional
By default, the aging time is
90 days.
Содержание 4210 PWR
Страница 10: ...Password Control Configuration 556 Displaying Password Control 563 Password Control Configuration Example 564...
Страница 22: ...20 CHAPTER 1 CLI CONFIGURATION...
Страница 74: ...72 CHAPTER 3 CONFIGURATION FILE MANAGEMENT...
Страница 84: ...82 CHAPTER 5 VLAN CONFIGURATION...
Страница 96: ...94 CHAPTER 8 IP PERFORMANCE CONFIGURATION...
Страница 108: ...106 CHAPTER 9 PORT BASIC CONFIGURATION...
Страница 122: ...120 CHAPTER 11 PORT ISOLATION CONFIGURATION...
Страница 140: ...138 CHAPTER 13 MAC ADDRESS TABLE MANAGEMENT...
Страница 234: ...232 CHAPTER 17 802 1X CONFIGURATION...
Страница 246: ...244 CHAPTER 20 AAA OVERVIEW...
Страница 270: ...268 CHAPTER 21 AAA CONFIGURATION...
Страница 292: ...290 CHAPTER 26 DHCP BOOTP CLIENT CONFIGURATION...
Страница 318: ...316 CHAPTER 29 MIRRORING CONFIGURATION...
Страница 340: ...338 CHAPTER 30 CLUSTER...
Страница 362: ...360 CHAPTER 33 SNMP CONFIGURATION...
Страница 368: ...366 CHAPTER 34 RMON CONFIGURATION...
Страница 450: ...448 CHAPTER 39 TFTP CONFIGURATION...
Страница 451: ......
Страница 452: ...450 CHAPTER 39 TFTP CONFIGURATION...
Страница 470: ...468 CHAPTER 40 INFORMATION CENTER...
Страница 496: ...494 CHAPTER 44 DEVICE MANAGEMENT...