22
Step Command Remarks
1.
Enter system view.
system-view
N/A
2.
Add a local user and
enter local user view.
local-user user-name
[
class
{
manage
|
network
} ]
By default, no local users exist.
3.
(Optional.) Configure
a password for the
local user.
•
For a network access user:
password
{
cipher
|
simple
}
string
•
For a device management
user:
{
In non-FIPS mode:
password
[ {
hash
|
simple
}
string
]
{
In FIPS mode:
password
The default settings are as follows:
•
In non-FIPS mode, no password is
configured for a local user. A local
user can pass authentication after
entering the correct username and
passing attribute checks.
•
In FIPS mode, no password is
configured for a local user. A local
user cannot pass authentication.
4.
(Optional.) Configure
a description for the
local user.
description text
By default, no description is configured
for a local user.
You can configure descriptions only for
network access users.
5.
Assign services to the
local user.
•
For a network access user:
service-type
{
lan-access
|
portal
}
•
For a device management
user:
{
In non-FIPS mode:
service-type
{
ftp
| {
http
|
https
|
ssh
|
telnet
|
terminal
} * }
{
In FIPS mode:
service-type
{
https
|
ssh
|
terminal
} *
By default, no services are authorized to
a local user.
6.
(Optional.) Place the
local user to the active
or blocked state.
state
{
active
|
block
}
By default, a local user is in active state
and can request network services.
7.
(Optional.) Set the
upper limit of
concurrent logins
using the local user
name.
access-limit max-user-number
By default, the number of concurrent
logins is not limited for the local user.
This command takes effect only when
local accounting is configured for the
local user. It does not apply to FTP,
SFTP, or SCP users, who do not
support accounting.
8.
(Optional.) Configure
binding attributes for
the local user.
bind-attribute
{
ip
ip-address
|
location
interface
interface-type
interface-number
|
mac
mac-address
|
vlan vlan-id
} *
By default, no binding attributes are
configured for a local user.
9.
(Optional.) Configure
authorization
attributes for the local
user.
authorization-attribute
{
acl
acl-number
|
idle-cut
minutes
|
ip-pool
ipv4-pool-name
|
ipv6-pool
ipv6-pool-name
|
session-timeout
minutes
|
url
url-string
|
user-profile
profile-name
|
user-role role-name
|
vlan
vlan-id
|
work-directory
directory-name
} *
The following default settings apply:
•
The working directory for FTP,
SFTP, and SCP users is the root
directory of the NAS. However, the
users do not have permission to
access the root directory.
•
The network-operator user role is
assigned to local users that are
created by a network-admin or
level-15 user.
10.
(Optional.) Configure
password control
•
Set the password aging time:
password-control aging
By default, the local user uses password
Содержание FlexFabric 5940 SERIES
Страница 251: ...238 ...