User Access And Authentication
RADIUS Configuration
\[Command] show radius global \[Purpose] Display terminal RADIUS configuration information. \[View] System view \[Use Cases] \[Command] show radius server {all | ip-address } \[Purpose] Display radius server configuration \[View] System view \[Use Cases] \[Command] radius global \[auth-type {pap|chap|mschapv2}] \[passkey passkey ] \[src-ip src-ip ] \[nas-ip nas-ip ] \[timeout timeout ] \[retransmit retransmit ] \[Purpose] Configure authentication parameters for the RADIUS server.
Local User Configuration
\[Command] show local-user brief \[Purpose] Display local user information \[View] System view \[Use Cases] \<font color="#1d50a2">show local-user brief\</font> \<font color="#1d05a2">This command display description table\</font> \[Command] show local-user block-conf \[Purpose] Displays the device's configured method for processing successive incorrect password entries by the user \[View] System view \[Use Cases] \[Command] show local-user blocked \[Purpose] Show locked users \[View] System view \[Use Cases] \[Command] show local-user password-control \[Purpose] Show user password complexity configuration \[View] System view \[Use Cases] \[Command] local-user name name passwd password no local-user \[Purpose] Create local user \[Parameter] \[View] System configuration view \[Use Cases] \[Command] local-user block-time time \[Purpose] Configure local users to continuously enter incorrect password account lockout time \[Parameter] \[View] System configuration view \[Notes] Locked for 5 minutes by default. \[Use Cases] \[Command] local-user retry-count count no local-user retry-count \[Purpose] Configure a limit on the number of consecutive incorrect password entries for local users \[Parameter] \[View] System configuration view \[Notes] By default, 5 attempts are allowed \[Use Cases] \[Command] local-user password-control enable no local-user password-control enable \[Purpose] Configure local user password complexity function \[View] System configuration view \[Notes] To prevent passwords from being cracked by malicious users through brute-force attacks, you can configure the complexity requirements for local user passwords.
AAA Configuration
\[Command] show aaa \[Purpose] View the authentication, authorization and billing settings configured in the network node \[View] System view \[Use Cases] \[Command] aaa accounting command {tacacs+|radius|local|default} \[Purpose] Configure AAA Audit Method \[Parameter] \[View] System configuration view \[Notes] After enabling TACACS+ or RADIUS auditing, commands executed by users at the command line will be logged on the TACACS+ server or RADIUS server. \[Use Cases] \[Command] aaa authentication debug enable no aaa authentication debug enable \[Purpose] Enable user authentication debug information \[View] System configuration view \[Notes] When users enable authentication debug information, corresponding authentication details for each user will be logged to the /var/log/syslog file during the authentication process.
TACACS Configuration
\[Command] show tacacs show tacacs config \[Purpose] Display terminal TACACS+ configuration information. \[View] System view \[Notes] After modifying device configurations, you can use this command to view information such as the authentication type, timeout period, and communication key for the TACACS terminal.