HPE Moonshot 45Gc Security Configuration Manual page 33

Switch module
Table of Contents

Advertisement

Step
5.
(Optional.) Place the local
user to the active or
blocked state.
6.
(Optional.) Set the upper
limit of concurrent logins
using the local user
name.
7.
(Optional.) Configure
binding attributes for the
local user.
8.
(Optional.) Configure
authorization attributes
for the local user.
9.
(Optional.) Configure
password control
attributes for the local
user.
Command
In non-FIPS mode:
service-type { ftp | { http |
https | ssh | telnet |
terminal } * }
In FIPS mode:
service-type { https | ssh
| terminal } *
state { active | block }
access-limit max-user-number
bind-attribute { ip ip-address |
location interface interface-type
interface-number | mac
mac-address | vlan vlan-id } *
authorization-attribute { acl
acl-number | idle-cut minute |
ip-pool pool-name | ipv6-pool
ipv6-pool-name | user-profile
profile-name | user-role role-name
| vlan vlan-id | work-directory
directory-name } *
Set the password aging time:
password-control aging
aging-time
Set the minimum password
length:
password-control length
length
Configure the password
composition policy:
password-control
composition type-number
type-number [ type-length
type-length ]
Configure the password
complexity checking policy:
password-control
complexity
{ same-character |
user-name } check
Configure the maximum login
attempts and the action to
take if there is a login failure:
password-control
login-attempt login-times
20
Remarks
By default, a created local user is in
active state and can request
network services.
By default, the number of concurrent
logins is not limited for the local
user.
This command takes effect only
when local accounting is configured
for the local user. It does not apply to
FTP, SFTP, or SCP users, who do
not support accounting.
By default, no binding attribute is
configured for a local user.
The following default settings apply:
FTP, SFTP, and SCP users
have the root directory of the
NAS set as the working
directory. However, the users
do not have permission to
access the root directory.
The network-operator user role
is assigned to local users that
are created by a
network-admin or level-15
user.
Optional.
By default, the local user uses
password control attributes of the
user group to which the local user
belongs.
Only device management users
support the password control
feature.

Advertisement

Table of Contents
loading

Table of Contents