UMN:CLI
User Manual
V8102
292
8.3.3
Primary Authentication Method
You can set the order of the authentication method by giving the priority to each authenti-
cation method.
To set the primary authentication method, use the following command
Command
Mode
Description
login
{
local
|
remote
} {
radius
|
tacacs
|
host
}
primary
Global
Sets a system authentication method.
local: console access
remote: telnet/SSH access
radius: RADIUS authentication
tacacs: authentication
host: nominal system authentication (default)
8.3.4
Automated Blocking of IP Host
For security reasons of the system, Administrator can configure the number of the login
fails to be blocked and configure the delay time for login attempts. To configure the login
delay function, use the following command.
Command
Mode
Description
ip auth-fail-block
Global
Enables login delay function based IP.
no ip auth-fail-block
Disables login delay function.
To set the expire-time of a blocked host for login, use the following command.
Command
Mode
Description
ip auth-fail-block expire-time
<1-
60>
Global
Configures the expire time of blocked host. (default:
300sec)
no ip auth-fail-block expire-time
Resetss the default time.
To set the max number of hosts to be blocked, use the following command.
Command
Mode
Description
ip auth-fail-block max-entry
<1-
512>
Global
Configures the max number of hosts to be blocked.
(default: 128)
no ip auth-fail-block max-entry
Resetss the default value.
To display the configured information about the blocking host function, use the following
command.
Command
Mode
Description
show ip auth-fail-block
[
entry
]
Enable
Global
Shows the information of blocking host function config-
ured.
clear ip auth-fail-block entry
[A.B.C.D]
Clears the blocking host function configured.