HP 6125XLG R2306-HP 6125XLG Blade Switch Security Command Reference - Page 31

display local-user

Page 31 highlights

mac mac-address: Specifies the MAC address of the user in the format H-H-H. This option applies only to LAN users. vlan vlan-id: Specifies the VLAN to which the user belongs. The vlan-id argument is in the range of 1 to 4094. This option applies only to LAN users. Usage guidelines Binding attributes are checked upon authentication of a local user. The user fails authentication in the following situations: • The binding attributes of the local user do not match the configured attributes. • The local user does not have the configured binding attributes. When you configure binding attributes for a local user, verify the following items: • The device can obtain from the user's packet all attributes for checking. For example, you can configure an IP address binding for an 802.1X user, because 802.1X authentication can include the user's IP address in the packet. However, you cannot configure IP address bindings for MAC authentication users, because their packets do not include user IP addresses. • The binding interface type must meet the requirements of the local user. For example, you can bind an 802.1X user to a physical port. If you bind the 802.1X user to a logical interface (for example, a VLAN interface), the user will fail the local authentication. Examples # Bind IP address 3.3.3.3 with the network access user abc. system-view [Sysname] local-user abc class network [Sysname-luser-network-abc] bind-attribute ip 3.3.3.3 Related commands display local-user display local-user Use display local-user to display the local user configuration and online user statistics. Syntax display local-user [ class { manage | network } | idle-cut { disable | enable } | service-type { ftp | lan-access | ssh | telnet | terminal } | state { active | block } | user-name user-name | vlan vlan-id ] Views Any view Predefined user roles network-admin network-operator Parameters class: Specifies the local user type. • manage: Device management user. • network: Network access user. idle-cut { disable | enable }: Specifies local users with the idle cut function disabled or enabled. 22

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321

22
mac
mac-address
: Specifies the MAC address of the user in the format H-H-H. This option applies only to
LAN users.
vlan
vlan-id
: Specifies the VLAN to which the user belongs. The
vlan-id
argument is in the range of 1 to
4094. This option applies only to LAN users.
Usage guidelines
Binding attributes are checked upon authentication of a local user. The user fails authentication in the
following situations:
The binding attributes of the local user do not match the configured attributes.
The local user does not have the configured binding attributes.
When you configure binding attributes for a local user, verify the following items:
The device can obtain from the user's packet all attributes for checking. For example, you can
configure an IP address binding for an 802.1X user, because 802.1X authentication can include the
user's IP address in the packet. However, you cannot configure IP address bindings for MAC
authentication users, because their packets do not include user IP addresses.
The binding interface type must meet the requirements of the local user. For example, you can bind
an 802.1X user to a physical port. If you bind the 802.1X user to a logical interface (for example,
a VLAN interface), the user will fail the local authentication.
Examples
# Bind IP address 3.3.3.3 with the network access user
abc
.
<Sysname> system-view
[Sysname] local-user abc class network
[Sysname-luser-network-abc] bind-attribute ip 3.3.3.3
Related commands
display local-user
display local-user
Use
display local-user
to display the local user configuration and online user statistics.
Syntax
display local-user
[
class
{
manage
|
network
} |
idle-cut
{
disable
|
enable
} |
service-type
{
ftp
|
lan-access
|
ssh
|
telnet
|
terminal
} |
state
{
active
|
block
} |
user-name
user-name
|
vlan
vlan-id
]
Views
Any view
Predefined user roles
network-admin
network-operator
Parameters
class
: Specifies the local user type.
manage
: Device management user.
network
: Network access user.
idle-cut
{
disable
|
enable
}: Specifies local users with the idle cut function disabled or enabled.