Authorization-Attribute (Local User View/User Group View) - HP A5500 EI Command Reference Manual

Hide thumbs Also See for A5500 EI:
Table of Contents

Advertisement

This limit is not effective for FTP users because accounting is not available for FTP users.
Related commands: display local-user.
Examples
# Limit the maximum number of concurrent users of local user account abc to 5.
<Sysname> system-view
[Sysname] local-user abc
[Sysname-luser-abc] access-limit 5

authorization-attribute (local user view/user group view)

Syntax
authorization-attribute { acl acl-number | callback-number callback-number | idle-cut minute | level level
| user-profile profile-name | user-role security-audit | vlan vlan-id | work-directory directory-name } *
undo authorization-attribute { acl | callback-number | idle-cut | level | user-profile | user-role | vlan |
work-directory } *
View
Local user view, user group view
Default level
3: Manage level
Parameters
acl acl-number: Specifies the authorization ACL. The ACL number must be in the range 2000 to 5999.
After passing authentication, a local user is authorized to access the network resources specified by this
ACL.
callback-number callback-number: Specifies the authorization PPP callback number. callback-number is a
case-sensitive string of 1 to 64 characters. After a local user passes authentication, the switch uses this
number to call the user.
idle-cut minute: Sets the idle timeout period. With the idle cut function enabled, an online user whose idle
period exceeds the specified idle timeout period will be logged out. minute indicates the idle timeout
period, in the range 1 to 120 minutes.
level level: Specifies the user level, which can be 0 for visit level, 1 for monitor level, 2 for system level,
and 3 for manage level. A smaller number means a lower level. If the user interfaces' authentication
mode is scheme, which commands users can use after login in depends on this argument. By default, the
user level is 0, and users can use only commands of level 0 after login.
user-profile profile-name: Specifies the authorization user profile. profile-name is a case-sensitive string of
1 to 32 characters. It can consist of English letters, digits, and underlines, and must start with an English
letter. After a user passes authentication and gets online, the switch uses the settings in the user profile to
restrict the access behavior of the user.
user-role security-audit: Specifies the role of the local user as security-audit. Users with different roles can
access different levels of commands. security-audit is used to specify the user as a security log
administrator. After passing authentication, a security log administrator is allowed to perform operations
to the security log files, such as saving operation. This attribute is supported in local user view only. For
more information about the commands that a security log administrator can use, see the Network
Management and Monitoring Configuration Guide.
26

Advertisement

Table of Contents
loading

This manual is also suitable for:

A5500 si

Table of Contents