29.04.2019 Views

OS6860(E)_AOS_8.1.1.R01_Switch_Management_Guide

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Managing <strong>Switch</strong> User Accounts<br />

Overview of User Accounts<br />

Default User Settings<br />

The default user account on the switch is used for storing new user defaults for privileges and profile<br />

information. This account does not include a password and cannot be used to log into the switch.<br />

At the first switch startup, the default user account is configured for:<br />

• No read or write access.<br />

• No SNMP access.<br />

Any new users created on the switch will inherit the privileges of the default user unless the user is configured<br />

with specific privileges.<br />

The default user settings may be modified. Enter the user command with default as the user name. Note<br />

that the default user may only store default functional privileges.<br />

The following example modifies the default user account with read-write access to all CLI commands:<br />

-> user default read-write all<br />

In this example, any new user that is created will have read and write access to all CLI commands (unless<br />

a specific privilege or SNMP access is configured for the new user).<br />

Account and Password Policy Settings<br />

The switch includes global password settings that are used to implement and enforce password complexity<br />

when a password is created, modified, and used. These user-configurable settings apply the following<br />

password requirements to all user accounts configured for the switch:<br />

• Minimum password size.<br />

• Whether or not a password can contain the account username.<br />

• Minimum password character requirements.<br />

• Password expiration.<br />

• Password history.<br />

• Minimum password age.<br />

In addition to global password settings, the switch also includes global user lockout settings that determine<br />

when a user account is locked out of the switch and the length of time the user account remains<br />

locked.<br />

See “Configuring Password Policy Settings” on page 6-10 and “Configuring Global User Lockout<br />

Settings” on page 6-13 for more information.<br />

How User Settings Are Saved<br />

Unlike other settings on the switch, user settings configured through the user and password commands<br />

are saved to the switch configuration automatically. These settings are saved in real time in the local user<br />

database.<br />

At bootup, the switch reads the database file for user information (rather than the vcboot.cfg file).<br />

Omni<strong>Switch</strong> <strong>AOS</strong> Release 8 <strong>Switch</strong> <strong>Management</strong> <strong>Guide</strong> May 2014 page 6-7

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!