enable user
enable user
{
disable-on-login-failure
[
invalid-attempts
login-recovery-time
{
in-hours
|
in-mins
|
in-secs
}
recovery-time
]
|
password-aging
|
password-history
[
previous-passwords
]
}no enable user
{
disable-on-login-failure
[
invalid-attempts
login-recovery-time
{
in-hours
|
in-mins
|
in-secs
}
recovery-time
]
|
password-aging
|
password-history
[
previous-passwords
]
}Three login attempts are allowed.
Three minutes of recovery time is enforced before another login attempt is allowed on user accounts.
In CC mode, the default recovery time is 3 seconds.
The ICX device stores the last five user passwords for each user.
- disable-on-login-failure invalid-attempts
- Specifies the number of login attempts before a user is locked out (disabled). The range is from 1 through 10. The default is 3.
- login-recovery-time { in-hours | in-mins | in-secs } recovery-time
- Specifies the recovery time in designated units
(hours, minutes, or seconds) after which a login can be attempted on the
locked-out user accounts.
Verify changes.The valid range for in-hours is 1 through 2. The valid range for in-minutes is 3 through 120. The valid range for in-seconds is 2 through 7200.
Global configuration mode
If a user fails to log in after three attempts, that user is locked out. You can increase or decrease the number of login attempts before the user is locked out.
After the user is locked out and the configured recovery time has elapsed, a valid login attempt unlocks the account. The account is not automatically reenabled after the recovery time. The number of attempts allowed still applies after the recovery time.
When password aging is enabled, the software records the system time that each user
password was configured or last changed. After 180 days, the CLI automatically prompts
users to change their passwords when they attempt to sign on. The time displays in
the output of the
show running configuration command, indicated by set-time.
When changing a user password, the user cannot use any of the five previously configured passwords. You can configure the ICX device to store up to 15 passwords for each user, so that users do not use the same password multiple times. If a user attempts to use a password that is stored, the system prompts the user to choose a different password.
The
no form of the command removes the login and password configurations.
The no form of enable user
disable-on-login-failure disables both the maximum number of login
attempts and recovery time configurations and resets the system to the default
for
both attempts and recovery time. To disable only the recovery time configuration,
use the no enable user
{
disable-on-login-failure
[
invalid-attempts
login-recovery-time
recovery-time
]
} command.
The following example sets the number of login attempts for a user to 10.
device(config)# enable user disable-on-login-failure 10
The following example configures the user account to automatically re-enable the locked-out users after 5 minutes of the lockout.
device(config)# enable user disable-on-login-failure 4 login-recovery-time in-mins 5