User Access And Authentication
TACACS Configuration
\[Command] show tacacs \[Purpose] Display terminal control configuration information \[View] System view \[Notes] After modifying the device configuration, this command can be used to view the authentication type, timeout period, and communication key information of the TACACS terminal with the server. \[Use Cases] \[Command] show tacacs status \[Purpose] Check the connection status between TACACS server and devices.
Local User Configuration
\[Command] show local-user brief \[Purpose] Display local user information \[View] System view \[Use Cases] show local-user brief This command display description table \[Command] show local-user block-conf \[Purpose] Displays the device's configured method for processing successive incorrect password entries by the user \[View] System view \[Use Cases] \[Command] show local-user blocked \[Purpose] Show locked users \[View] System view \[Use Cases] \[Command] local-user name name passwd password no local-user name \[Purpose] Create local user \[Parameter] \[View] System configuration view \[Use Cases] \[Command] local-user block-time time \[Purpose] Configure local users to continuously enter incorrect password account lockout time \[Parameter] \[View] System configuration view \[Notes] Locked for 5 minutes by default. \[Use Cases] \[Command] local-user retry-count count no local-user retry-count \[Purpose] Configure a limit on the number of consecutive incorrect password entries for local users \[Parameter] \[View] System configuration view \[Notes] By default, 5 attempts are allowed \[Use Cases] \[Command] local-user password-control enable|min-len|min-lowercase|min-uppercase|min-digits|min-special-chars|expiration-time|expiration-warning no local-user password-control enable|min-len|min-lowercase|min-uppercase|min-digits|min-special-chars|expiration-time|expiration-warning \[Purpose] Configure security rules such as local user password strength settings and expiration dates \[Parameter] \[View] System configuration view \[Notes] To ensure sufficient password strength for local users, the strength of password configuration can be set.
RADIUS Configuration
\[Command] show radius {server|global|null} \[Purpose] Display configuration information related to the radius service, including viewing the global configuration of radius and configuration parameters of each server. \[View] System view \[Notes] After modifying the device configuration, this command can be used to view information such as the authentication type, timeout period, and key used for communication with the server in the radius authentication system.
AAA Configuration
\[Command] show aaa \[Purpose] View the authentication, authorization and billing settings configured in the network node \[View] System view \[Use Cases] \[Command] show tacacs status \[Purpose] Display the TACACS server status \[View] System view \[Use Cases] \[Command] aaa accounting command {tacacs+|local|default} \[Purpose] Configure AAA billing method \[Parameter] \[View] System configuration view \[Notes] Tacacs+ and local can be used individually or in combination. \[Use Cases] \[Command] aaa authentication failthrough {enable|default} no aaa authentication failthrough enable \[Purpose] Enable fail-through \[Parameter] default Default enable Enable \[View] System configuration view \[Notes] This command is useful when the user has multiple tacacs + servers configured and the user has tacacs+ authentication enabled.
License Configuration
\[Command] show license \[Purpose] View license information \[View] System view \[Notes] To view license details, including its name, creation date, expiration date, and current activation status \[Use Cases] \[Command] license update \[Purpose] Update license \[View] System view \[Notes] To update the license, copy a valid license file to the /etc/sonic/lic/ directory \[Use Cases]