19
Step Command
Remarks
6.
Set the maximum number of
concurrent users of the local
user account.
access-limit
max-user-number
Optional.
By default, there is no limit to the
maximum number of concurrent
users of a local user account.
The limit is effective only for local
accounting, and is not effective for
FTP users.
7.
Configure the password
control attributes for the local
user.
•
Set the password aging time:
password-control aging
aging-time
•
Set the minimum password
length:
password-control length
length
•
Configure the password
composition policy:
password-control composition
type-number
type-number
[
type-length
type-length
]
Optional.
By default, the local user uses
password control attributes of the
user group to which the local user
belongs, and uses the global
setting for any password control
attribute that is not configured in
the user group.
For more information about
password control configuration
commands, see
Security
Command Reference
.
8.
Configure the binding
attributes for the local user.
bind-attribute
{
ip
ip-address
|
location
port
slot-number
subslot-number
port-number
|
mac
mac-address
|
vlan
vlan-id
} *
Optional.
By default, no binding attribute is
configured for a local user.
9.
Configure the authorization
attributes for the local user.
authorization-attribute
{
acl
acl-number
|
idle-cut
minute
|
level
level
|
user-profile
profile-name
|
user-role
{
guest
|
guest-manager
|
security-audit
} |
vlan
vlan-id
|
work-directory
directory-name
} *
Optional.
By default, no authorization
attribute is configured for a local
user.
For LAN and portal users, only
acl
,
idle-cut
,
user-profile
, and
vlan
are
supported.
For SSH, terminal, and Web users,
only
level
is supported.
For FTP users, only
level
and
work-directory
are supported.
For Telnet users, only
level
and
user-role
is supported.
For other types of local users, no
binding attribute is supported.
10.
Set the validity time of the
local user.
validity-date
time
Optional.
Not set by default.
11.
Set the expiration time of the
local user.
expiration-date
time
Optional.
Not set by default.
12.
Assign the local user to a user
group.
group
group-name
Optional.
By default, a local user belongs to
the default user group
system
.