HPE Moonshot 45Gc Security Configuration Manual page 32

Switch module
Table of Contents

Advertisement

information about password management and global password configuration, see "Configuring
password control."
Local user configuration task list
Tasks at a glance
(Required.)
(Optional.)
Configuring user group attributes
(Optional.)
Displaying and maintaining local users and local user groups
Configuring local user attributes
When you configure local user attributes, follow these guidelines:
When you use the password-control enable command to globally enable the password
control feature, local user passwords are not displayed.
You can configure authorization attributes and password control attributes in local user view or
user group view. The setting in local user view takes precedence over the setting in user group
view.
Configure the location binding attribute based on the service types of users.
For 802.1X users, specify the 802.1X-enabled Layer 2 Ethernet interfaces through which
the users access the device.
For MAC authentication users, specify the MAC authentication-enabled Layer 2 Ethernet
interfaces through which the users access the device.
For portal users, specify the portal-enabled interfaces through which the users access the
device. Specify the Layer 2 Ethernet interfaces if portal is enabled on VLAN interfaces and
the portal roaming enable command is not configured.
To configure local user attributes:
Step
1.
Enter system view.
2.
Add a local user and enter
local user view.
3.
(Optional.) Configure a
password for the local
user.
4.
Assign services to the
local user.
Configuring local user attributes
Command
system-view
local-user user-name [ class
{ manage | network } ]
For a network access user:
password { cipher | simple }
password
For a device management
user:
In non-FIPS mode:
password [ { hash |
simple } password ]
In FIPS mode:
password
For a network access user:
service-type { lan-access |
portal }
For a device management
user:
19
Remarks
N/A
By default, no local user exists.
Network access user passwords are
encrypted with the encryption
algorithm and saved in ciphertext.
Device management user
passwords are encrypted with the
hash algorithm and saved in
ciphertext.
In non-FIPS mode, a
non-password-protected user
passes authentication if the user
provides the correct username and
passes attribute checks. To
enhance security, configure a
password for each local user.
In FIPS mode, only
password-protected users can pass
authentication.
By default, no service is authorized
to a local user.

Advertisement

Table of Contents
loading

Table of Contents