
1-19
A local user represents a set of user attributes configured on a device and is uniquely identified by the
username. For a user requesting a network service to pass local authentication, you must add an entry
for it in the local user database of the device as follows: create a local user and configure attributes in
local user view. Configurable local user attributes include:.
z
Service type
Local authentication checks the service types of a local user. If the service types are not available, the
user cannot pass authentication.
You can specify the service types for a user, including FTP, LAN access, SSH, Telnet and Terminal.
z
User state
There are two user states, active and block.
active
means the user is allowed to request network
services.
block
means the user is not allowed to request network services.
z
Maximum user number
The maximum user number specifies the maximum number of access users that can use the current
username. If the number is reached, subsequent users using the same username are denied to access.
z
Expiration time
During authentication, the access device checks the expiration time of each requesting user. If the
expiration time of a user is reached, the user is not allowed to log in.
z
User group
Each local user belongs to a local user group and bears all attributes of the group, such as authorization
attributes. For details about local user group, refer to
Configuring User Group Attributes
.
z
Binding attributes
Binding attributes, including the ISDN calling number, IP address, access port, MAC address and VLAN
of a user, are checked during authentication. If a requesting user’s attributes do not match the binding
attributes configured for it on the access device, the user cannot pass authentication.
z
Authorization attributes
You can configure an authorization attribute in user group view or local user view, making the attribute
effective on all local users of the group or only the local user. An authorization attribute configured in
local user view takes precedence over the same attribute configured in user group view.
A user passing authentication gets the authorization attributes configured for it, including ACL, PPP
callback number, user level, user profile, VLAN, and FTP/SFTP work directory.
Follow these steps to configure the attributes for a local user:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Set the password display mode for
all local users
local-user
password-display-mode
{
auto
|
cipher-force
}
Optional
auto
by default, indicating
to display the password of
a local user in the way
indicated by the
password
command.
Add a local user and enter local
user view
local-user user-name
Required
No local user exists by
default.
Configure a password for the local
user
password
{
cipher
|
simple
}
password
Optional
Содержание S5120-EI Series
Страница 139: ...ii...
Страница 268: ...3 3 SwitchB system view SwitchB interface vlan interface 1 SwitchB Vlan interface1 ip address dhcp alloc...
Страница 328: ...i Table of Contents 1 Dual Stack Configuration 1 1 Dual Stack Overview 1 1 Configuring Dual Stack 1 1...
Страница 578: ...1 21 C...
Страница 739: ...1 12 Enable ARP detection based on 802 1X security entries SwitchB arp detection mode dot1x...
Страница 926: ...2 8...
Страница 942: ...ii Single Device Upgrade 3 4 IRF System Upgrade 3 5...
Страница 985: ...1 1...
Страница 1018: ...1 6...