23
Step Command Remarks
attributes for the local
user.
aging-time
•
Set the minimum password
length:
password-control length
length
•
Configure the password
composition policy:
password-control
composition type-number
type-number
[
type-length
type-length
]
•
Configure the password
complexity checking policy:
password-control
complexity
{
same-character
|
user-name
}
check
•
Configure the maximum login
attempts and the action to
take if there is a login failure:
password-control
login-attempt login-times
[
exceed
{
lock
|
lock-time
time
|
unlock
} ]
control attributes of the user group to
which the local user belongs.
Only device management users support
the password control feature.
11.
(Optional.) Assign the
local user to a user
group.
group
group-name
By default, a local user belongs to the
user group
system
.
12.
Configure the validity
period for the local
user.
validity-datetime
{
from start-date
start-time to expiration-date
expiration-time | from start-date
start-time
|
to
expiration-date
expiration-time
}
By default, a local user does not expire.
You can configure validity periods only
for network access users.
Configuring user group attributes
User groups simplify local user configuration and management. A user group contains a group of
local users and has a set of local user attributes. You can configure local user attributes for a user
group to implement centralized user attributes management for the local users in the group. Local
user attributes that are manageable include authorization attributes.
By default, every new local user belongs to the default user group
system
and has all attributes of
the group. To assign a local user to a different user group, use the
group
command in local user
view.
To configure user group attributes:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Create a user group and
enter user group view.
user-group group-name
By default, a system-defined
user group exists. The group
name is system.
3.
Configure authorization
attributes for the user
group.
authorization-attribute
{
acl
acl-number
|
idle-cut
minutes
|
ip-pool
ipv4-pool-name
|
ipv6-pool
ipv6-pool-name
|
session-timeout
minutes
|
url
url-string
|
user-profile
profile-name
|
vlan
vlan-id
|
work-directory
directory-name
} *
By default, no authorization
attributes are configured for a
user group.
Содержание FlexFabric 5940 SERIES
Страница 251: ...238 ...