Parameters
lockout-duration
minutes
Specifies the number of minutes to lock out an account after exceeding the
maximum number of failed login attempts. A value of 0 indicates that
accounts are locked out until reset by a privileged administrator. Use an
integer in the range of 0 through 1000. The default is 1.
max-login-failure
count
Specifies the maximum number of failed login attempts to allow before
lockout. A value of 0 disables account lockout. Use an integer in the range
of 0 through 64. The default is 3.
Context
Available only when the appliance is in Common Criteria mode.
Guidelines
The
account
command defines whether to lock out a local user account after a
specific number of failed login attempts and, if lockout is enabled, the duration to
lock out the local account. To enable lockout behavior and define the duration to
lock out the account requires two invocations of the
account
command.
v
An invocation with the
max-login failure
parameter defines the number of
failed login attempts to permit before a successful login. If the value is 3 and the
user has failed three consecutive login attempts, the behavior on the next login
attempt for this user is as follows:
– If failure, the account is locked out. The duration of the lockout depends on
the value defined by the
lockout-duration
parameter.
– If successful, the account is not locked out and the count is reset.
If the value is 0, lockout behavior is disabled. Repeated successive login failures
by a user do not cause lockout of that account.
v
An invocation with the
lockout-duration
parameter defines the duration to lock
out an account after exceeding the permitted number of failed login attempts
defined by the invocation with the
max-login failure
command. Instead of
locking out an account for a specific duration, the account can be locked out
until re-enabled by a privileged administrator. To lock out accounts until reset,
set the duration to 0.
When lockout behavior is enabled and an account is locked out, a privileged
administrator can use the Global
reset username
command to re-enable the
account. To re-enabled the account
1.
The administrator will change the password on the account with the
reset
username
command.
2.
The user will be prompted to again change the password on initial login.
Note:
The
account
command applies to all accounts including the
admin
account.
The only difference is that the
admin
account cannot be locked out until
reset. When the duration is 0, the
admin
account is locked out for 120
minutes or until re-enabled by another administrator.
Related Commands
reset username
20
Command Reference
Summary of Contents for WebSphere XS40
Page 1: ...WebSphere DataPower XML Security Gateway XS40 Command Reference Version 3 7 2 ...
Page 2: ......
Page 3: ...WebSphere DataPower XML Security Gateway XS40 Command Reference Version 3 7 2 ...
Page 44: ...18 Command Reference ...
Page 194: ...168 Command Reference ...
Page 198: ...172 Command Reference ...
Page 206: ...180 Command Reference ...
Page 210: ...184 Command Reference ...
Page 222: ...196 Command Reference ...
Page 232: ...206 Command Reference ...
Page 238: ...212 Command Reference ...
Page 268: ...242 Command Reference ...
Page 272: ...246 Command Reference ...
Page 276: ...250 Command Reference ...
Page 288: ...262 Command Reference ...
Page 292: ...266 Command Reference ...
Page 298: ...272 Command Reference ...
Page 320: ...294 Command Reference ...
Page 322: ...296 Command Reference ...
Page 340: ...314 Command Reference ...
Page 344: ...318 Command Reference ...
Page 352: ...326 Command Reference ...
Page 360: ...334 Command Reference ...
Page 368: ...342 Command Reference ...
Page 376: ...350 Command Reference ...
Page 386: ...360 Command Reference ...
Page 392: ...366 Command Reference ...
Page 396: ...370 Command Reference ...
Page 402: ...376 Command Reference ...
Page 404: ...378 Command Reference ...
Page 408: ...382 Command Reference ...
Page 446: ...420 Command Reference ...
Page 450: ...424 Command Reference ...
Page 456: ...430 Command Reference ...
Page 520: ...494 Command Reference ...
Page 536: ...510 Command Reference ...
Page 550: ...524 Command Reference ...
Page 584: ...558 Command Reference ...
Page 600: ...574 Command Reference ...
Page 605: ... timeout 500 Chapter 63 RADIUS configuration mode 579 ...
Page 606: ...580 Command Reference ...
Page 650: ...624 Command Reference ...
Page 668: ...642 Command Reference ...
Page 704: ...678 Command Reference ...
Page 714: ...688 Command Reference ...
Page 726: ...700 Command Reference ...
Page 734: ...708 Command Reference ...
Page 752: ...726 Command Reference ...
Page 756: ...730 Command Reference ...
Page 804: ...778 Command Reference ...
Page 880: ...854 Command Reference ...
Page 892: ...866 Command Reference ...
Page 912: ...886 Command Reference ...
Page 918: ...892 Command Reference ...
Page 940: ...914 Command Reference ...
Page 946: ...920 Command Reference ...
Page 974: ...948 Command Reference ...
Page 1004: ...978 Command Reference ...
Page 1030: ...1004 Command Reference ...
Page 1032: ...1006 Command Reference ...
Page 1065: ......
Page 1066: ... Printed in USA ...