H3C—S7000系列交换机安全加固

[Core_Switch_S7006]user-interface ?
INTEGER<0-33> First user terminal interface number to be configured
aux Aux user terminal interface
vty Virtual user terminal interface
[Core_Switch_S7006]user-interface aux 0 #用户界面aux
[Core_Switch_S7006-ui-aux0]authentication-mode ? #认证模式
none Login without checking
password Authentication use password of user terminal interface
scheme Authentication use AAA
[Core_Switch_S7006-ui-aux0]q
[Core_Switch_S7006]local-user test #本地用户test
New local user added.
[Core_Switch_S7006-luser-test]password ?
cipher Specify a ciphertext password
hash Save and display the hash value of the password
simple Specify a plaintext password

[Core_Switch_S7006-luser-test]password cipher test1234 #设置test用户密码test1234
[Core_Switch_S7006-luser-test]authorization-attribute ? #属性委托授权
acl Specify ACL number of user
callback-number Specify dialing character string for callback user
idle-cut Specify idle-cut of local user
level Specify level of user
user-profile Specify user profile of user
user-role Specify role of local user
vlan Specify VLAN ID of user
work-directory Specify directory of user
[Core_Switch_S7006-luser-test]authorization-attribute level ? #属性委托授权级别
INTEGER<0-3> Level of user

[Core_Switch_S7006-luser-test]authorization-attribute level 3 ##属性委托授权级别3
[Core_Switch_S7006-luser-test]service-type ? #设定本地用户类型 /服务型
ftp FTP service type
lan-access LAN-ACCESS service type
portal Portal service type
ssh Secure Shell service type
telnet TELNET service type
terminal TERMINAL service type
web Web service type
[Core_Switch_S7006-luser-test]service-type terminal #设定本地用户服务型终端
[Core_Switch_S7006-luser-test]display th #显示当下用户信息

local-user test
password cipher $c 3 3 3oQmHfCHilD5mU1UFyV+4bagP2UBdUk8n0kYG
authorization-attribute level 3
service-type terminal

return
[Core_Switch_S7006-luser-test]q
[Core_Switch_S7006]user-interface aux 0
[Core_Switch_S7006-ui-aux0]authentication-mode ? #认证模式
none Login without checking
password Authentication use password of user terminal interface
scheme Authentication use AAA
[Core_Switch_S7006-ui-aux0]authentication-mode scheme #认证模式scheme
[Core_Switch_S7006-ui-aux0]q
[Core_Switch_S7006]local-user admin #本地用户admin
[Core_Switch_S7006-luser-admin]password ?
cipher Specify a ciphertext password
hash Save and display the hash value of the password
simple Specify a plaintext password

[Core_Switch_S7006-luser-admin]password cipher admin1234 #设置admin用户密码admin1234
[Core_Switch_S7006-luser-admin]display th #显示当下用户信息

local-user admin
password cipher $c 3 3 3VuMPH75DONX+IeMNdtzmiuxmAlwMrN8VKzEaEA==
authorization-attribute level 3
service-type ssh terminal

return
[Core_Switch_S7006-luser-admin]local-user test
[Core_Switch_S7006-luser-test]display th

local-user test
password cipher $c 3 3 3oQmHfCHilD5mU1UFyV+4bagP2UBdUk8n0kYG
authorization-attribute level 3
service-type terminal

return
[Core_Switch_S7006]local-user sysadmin #本地用户sysadmin
[Core_Switch_S7006-luser-sysadmin]display th

local-user sysadmin
password cipher $c$3$8/SOA19R9KrHvYigKqpf7c5cfFZhIB7UYK8N08w=
authorization-attribute level 2
service-type ssh

return
[Core_Switch_S7006-luser-sysadmin]service-type terminal #设定本地用户服务型终端
[Core_Switch_S7006-luser-sysadmin]dis th

local-user sysadmin
password cipher $c$3$8/SOA19R9KrHvYigKqpf7c5cfFZhIB7UYK8N08w=
authorization-attribute level 2
service-type ssh terminal

return
[Core_Switch_S7006-luser-sysadmin]password cipher sysadmin1234
[Core_Switch_S7006-luser-sysadmin]q
[Core_Switch_S7006]

[Core_Switch_S7006]password-control ? #密码控制
aging Specify password aging time
alert-before-expire Specify alert time before password expired
authentication-timeout Specify authentication timeout
complexity Specify password complexity
composition Specify composition of password
enable Enable password control globally
expired-user-login Specify user login with expired password
history Specify maximum history record
length Specify minimum length of password
login Specify local user’s login
login-attempt Specify local user’s login attempts
password Specify password
super Super user’s password controls
[Core_Switch_S7006]password-control aging 80 #密码过期时间为80天
[Core_Switch_S7006]password-control length 8 #密码长度最小为8为
[Core_Switch_S7006]password-control login-attempt 10 exceed lock-time 10 #密码输入错误10次锁定10分钟
[Core_Switch_S7006]password-control enable … #开启口令控制
Info: Password control is enabled.
[Core_Switch_S7006]user-interface aux 0
[Core_Switch_S7006-ui-aux0]idle-timeout 15 #终端登录超时为15分钟
[Core_Switch_S7006-ui-aux0]display th

user-interface aux 0
authentication-mode scheme
idle-timeout 15 0
user-interface aux 1
user-interface vty 0 15
authentication-mode scheme

return
[Core_Switch_S7006-ui-aux0]q

  • 0
    点赞
  • 2
    收藏
    觉得还不错? 一键收藏
  • 1
    评论
评论 1
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值