Configuring The Attributes Of A Local User - H3C S5100-SI Operation Manual

Ethernet switches
Hide thumbs Also See for H3C S5100-SI:
Table of Contents

Advertisement

Configuring the Attributes of a Local User

When local scheme is chosen as the AAA scheme, you should create local users on the switch and
configure the relevant attributes.
The local users are users set on the switch, with each user uniquely identified by a username. To make
a user who is requesting network service pass local authentication, you should add an entry in the local
user database on the switch for the user.
Follow these steps to configure the attributes of a local user:
To do...
Enter system view
Set the password display mode
of all local users
Add a local user and enter local
user view
Set a password for the local
user
Set the status of the local user
Authorize the user to access
specified type(s) of service
Set the privilege level of the
user
Configure the authorized VLAN
for the local user
Set the attributes of the user
whose service type is
lan-access
Use the command...
system-view
local-user
password-display-mode
{ cipher-force | auto }
local-user user-name
password { simple | cipher }
password
state { active | block }
service-type { ftp | lan-access
| { telnet | ssh | terminal }*
[ level level ] }
level level
authorization vlan string
attribute { ip ip-address | mac
mac-address | idle-cut second
| access-limit
max-user-number | vlan vlan-id
| location { nas-ip ip-address
port port-number | port
port-number } }*
2-7
Remarks
Optional
By default, the password
display mode of all access
users is auto, indicating the
passwords of access users are
displayed in the modes set by
the password command.
Required
By default, there is no local
user in the system.
Required
Optional
By default, the user is in active
state, that is, the user is
allowed to request network
services.
Required
By default, the system does not
authorize the user to access
any service.
Optional
By default, the privilege level of
the user is 0.
Required
By default, no authorized VLAN
is configured for the local user.
Optional
When binding the user to a
remote port, you must use
nas-ip ip-address to specify a
remote access server IP
address (here, ip-address is
127.0.0.1 by default,
representing this device).
When binding the user to a
local port, you need not use
nas-ip ip-address.

Advertisement

Table of Contents
loading

This manual is also suitable for:

H3c s5100-ei

Table of Contents