
37
Ste
Command
Remarks
4. Enter one or multiple VTY user
interface views.
user-interface vty first-number
[ last-number ]
N/A
5. Enable scheme
authentication.
authentication-mode scheme
By default, the authentication
mode for VTY user interfaces is
scheme.
6. Enable the user interfaces to
support Telnet, SSH, or both
of them.
protocol inbound { all | ssh }
Optional.
By default, both Telnet and SSH
are supported.
7. Enable command
authorization.
command authorization
Optional.
By default, command authorization
is disabled. The commands
available for a user only depend
on the user privilege level.
8. Enable command accounting.
command accounting
Optional.
By default, command accounting is
disabled. The accounting server
does not record the commands
executed by users.
9. Exit to system view.
quit N/A
10. Apply an AAA authentication
scheme to the intended
domain.
a. Enter the ISP domain view:
domain domain-name
b. Apply the specified AAA
scheme to the domain:
authentication default
{ hwtacacs-scheme
hwtacacs-scheme-name
[ local ] | ldap-scheme
ldap-scheme-name
[ local ]| local | none |
radius-scheme
radius-scheme-name
[ local ] }
c. Exit to system view:
quit
Optional.
For local authentication, configure
local user accounts.
For RADIUS or HWTACACS
authentication, configure the
RADIUS or HWTACACS scheme
on the device and configure
authentication settings (including
the username and password) on
the server.
For more information about AAA
configuration, see Access Control
Configuration Guide.
11. Create a local user and enter
local user view.
local-user user-name
By default, a local user named
admin exists.
12. Set a password for the local
user.
password { cipher | simple }
password
By default, the password for
system-predefined user admin is
admin, and no password is set for
any other local user.
13. Specify the command level of
the user.
authorization-attribute level level
Optional.
By default, the command level is 0.
Comentarios a estos manuales