HP 6125XLG R2306-HP 6125XLG Blade Switch Security Configuration Guide - Page 31

Displaying and maintaining local users and local user groups, Configuring RADIUS schemes - command reference

Page 31 highlights

Step 1. Enter system view. Command system-view Remarks N/A 2. Create a user group and enter its view. user-group group-name By default, there is a system-defined user group named system, which is the default user group. authorization-attribute { acl 3. Configure authorization acl-number | idle-cut minute | vlan attributes for the user group. vlan-id | work-directory directory-name } * By default, no authorization attribute is configured for a user group. 4. (Optional.) Configure password control attributes for the user group. Optional. • Set the password aging time: password-control aging aging-time By default, the user group uses global settings, including a 90-day password aging time, a • Set the minimum password length: minimum password length of 10 password-control length length characters, and at least one • Configure the password password composition type and composition policy: at least one character required password-control composition for each password composition type-number type-number type. For more information about [ type-length type-length ] password control commands, see Security Command Reference. Displaying and maintaining local users and local user groups Execute display commands in any view. Task Display the local user configuration and online user statistics. Display the user group configuration. Command display local-user [ class { manage | network } | idle-cut { disable | enable } | service-type { ftp | lan-access | ssh | telnet | terminal } | state { active | block } | user-name user-name | vlan vlan-id ] display user-group [ group-name ] Configuring RADIUS schemes A RADIUS scheme specifies the RADIUS servers that the device can work with and defines a set of parameters that the device uses to exchange information with the RADIUS servers, including the IP addresses of the servers, UDP port numbers, shared keys, and server types. Configuration task list Tasks at a glance (Required.) Creating a RADIUS scheme (Required.) Specifying the RADIUS authentication servers (Optional.) Specifying the RADIUS accounting servers and the relevant parameters (Optional.) Specifying the shared keys for secure RADIUS communication 22

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276

22
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Create a user group and
enter its view.
user-group
group-name
By default, there is a
system-defined user group named
system
, which is the default user
group.
3.
Configure authorization
attributes for the user group.
authorization-attribute
{
acl
acl-number
|
idle-cut
minute
|
vlan
vlan-id
|
work-directory
directory-name
} *
By default, no authorization
attribute is configured for a user
group.
4.
(Optional.) Configure
password control attributes
for the user group.
Set the password aging time:
password-control aging
aging-time
Set the minimum password length:
password-control length
length
Configure the password
composition policy:
password-control composition
type-number
type-number
[
type-length
type-length
]
Optional.
By default, the user group uses
global settings, including a
90-day password aging time, a
minimum password length of 10
characters, and at least one
password composition type and
at least one character required
for each password composition
type. For more information about
password control commands, see
Security Command Reference
.
Displaying and maintaining local users and local user groups
Execute
display
commands in any view.
Task
Command
Display the local user
configuration and online user
statistics.
display local-user
[
class
{
manage
|
network
} |
idle-cut
{
disable
|
enable
}
|
service-type
{
ftp
|
lan-access
|
ssh
|
telnet
|
terminal
} |
state
{
active
|
block
} |
user-name
user-name
|
vlan
vlan-id
]
Display the user group
configuration.
display user-group
[
group-name
]
Configuring RADIUS schemes
A RADIUS scheme specifies the RADIUS servers that the device can work with and defines a set of
parameters that the device uses to exchange information with the RADIUS servers, including the IP
addresses of the servers, UDP port numbers, shared keys, and server types.
Configuration task list
Tasks at a glance
(Required.)
Creating a RADIUS scheme
(Required.)
Specifying the RADIUS authentication servers
(Optional.)
Specifying the RADIUS accounting servers and the relevant parameters
(Optional.)
Specifying the shared keys for secure RADIUS communication