18
To do…
Use the command…
Remarks
Configure the
password
composition
policy
password-control composition
type-number
type-number
[
type-length
type-length
]
Optional
By default, the setting for the
user group is used. If there is no
such setting for the user group,
the global setting is used.
Specify the service types for the local
user
service-type
{
ftp
|
lan-access
|
{
ssh
|
telnet
|
terminal
} * |
portal
}
Required
By default, no service is
authorized to a local user.
Configure the binding attributes for
the local user
bind-attribute
{
call-number
call-
number
[
:
subcall-number
] |
ip
ip-address
|
location
port
slot-
number subslot-number
port-
number
|
mac
mac-address
|
vlan
vlan-id
} *
Optional
By default, no binding attribute
is configured for a local user.
ip
,
location
,
mac
, and
vlan
are
supported for LAN users. No
binding attribute is supported for
other types of local users.
Configure the authorization attributes
for the local user
authorization-attribute
{
acl
acl-
number
|
callback-number
callback-number
|
idle-cut
minute
|
level
level
|
user-
profile
profile-name
|
user-role
security-audit
|
vlan
vlan-id
|
work-directory
directory-name
}
*
Optional
By default, no authorization
attribute is configured for a local
user.
For LAN and portal users, only
acl
,
idle-cut
,
user-profile
, and
vlan
are supported.
For SSH and terminal users, only
level
is supported.
For FTP users, only
level
and
work-directory
are supported.
For Telnet users, only
level
and
user-role
is supported.
For other types of local users, no
binding attribute is supported.
Set the expiration time of the local
user
expiration-date
time
Optional
Not set by default
When some users need to
access the network temporarily,
create a guest account and
specify an expiration time for the
account.
Assign the local user to a user group
group
group-name
Optional
By default, a local user belongs
to the default user group
system
.