User Accounts Overview

Up to 32 local user accounts can be defined on a RUCKUS device. User accounts regulate who can access the management functions in the CLI.

You can create accounts for local users with passwords. Accounts passwords are encrypted. You can assign privilege levels to local user accounts.

Note: An ICX switch new from the factory includes a local account with Super-User privileges. You must retain a local account with Super-User privileges to create new users or set user privilege levels.
Note: FastIron 09.0.10a and later releases support only SHA-512 encryption for local user accounts. The following encryption types are deprecated:
  • service password-encryption sha1
  • service password-encryption sha256

Any user account created with one of the deprecated encryption methods is deleted when the ICX switch is upgraded to FastIron release 09.0.10a or later.

User accounts regulate access to the management functions in the CLI using the following methods:

  • Telnet access
  • Web management access
  • SNMP access
  • RESTCONF
  • SSH access─SSH refers to SSHv2, which is supported on all RUCKUS ICX devices.

For each local user account, you specify a user name and password. You also can specify the management privilege level, which can be one of the following:

  • 0 - Super User level (default) - Allows complete read-and-write access to the system. This is generally for system administrators and is the only privilege level that allows you to configure passwords.
  • 4 - Port Configuration level - Allows read-and-write access for specific ports, but not for global parameters.
  • 5 - Read Only level - Allows access to the Privileged EXEC mode and User EXEC mode with read access only.

User Account Guidelines

Be aware of the following guidelines for user accounts.

  • If the message of the day (MOTD) is configured, it will be displayed after the Telnet, SSH, or console session is successfully authenticated. The MOTD is configured using the banner motd command.
  • Users are locked out (disabled) if they fail to login after three attempts. This feature is automatically enabled. Use the disable-on-login-failure command to change the number of login attempts (up to 10) before users are locked out.