15
To do…
Use the command…
Remarks
Enter user interface view
user-interface
{
first-num1
[
last-num1
] | {
aux
|
vty
}
first-num2
[
last-num2
] }
—
Specify the scheme authentication
mode
authentication-mode
scheme
Required
By default, the authentication
mode for VTY users is
password
,
and no authentication is needed
for AUX login users.
Return to system view
quit
—
Configure the authentication mode
for SSH users as
password
For more information, see
Security
Configuration Guide.
Required if users use SSH to log in,
and username and password are
needed at authentication
Using local
authentication
•
Use the
local-user
command to
create a local user and enter
local user view.
•
Use the
level
keyword in the
authorization-attribute
command to configure the user
privilege level.
Configure the
user privilege
level by using
AAA
authentication
parameters
Using remote
authentication
(RADIUS or
HWTACACS
authentication)
Configure the user privilege level
on the authentication server
User either approach
•
For local authentication, if you
do not configure the user
privilege level, the user
privilege level is 0.
•
For remote authentication, if
you do not configure the user
privilege level, the user
privilege level depends on the
default configuration of the
authentication server.
Example of configuring a user privilege level by using AAA authentication parameters
# Authenticate users who telnet to the switch through VTY 1, verify their usernames and passwords, and
specify the user privilege level as 3.
<Sysname> system-view
[Sysname] user-interface vty 1
[Sysname-ui-vty1] authentication-mode scheme
[Sysname-ui-vty1] quit
[Sysname] local-user test
[Sysname-luser-test] password cipher 12345678
[Sysname-luser-test] service-type telnet
When users telnet to the switch through VTY 1, they need to enter the username
test
and password
12345678
. After passing authentication, the users can only use level 0 commands. If the users want to use
commands of level 0, 1, 2 and 3 commands, the following configuration is required:
[Sysname-luser-test] authorization-attribute level 3
Configure the user privilege level under a user interface
•
If the user interface authentication mode is
scheme
, and SSH
publickey
authentication type (only a
username is needed for this authentication type) is adopted, the user privilege level of users logging
into the user interface is the user interface level.
•
If the user interface authentication mode is
none
or
password
, the user privilege level of users
logging into the user interface is the user interface level.