Configuring Local User Accounts

You must be logged in with Super User access (privilege level 0) to add or delete user accounts or configure or modify other access parameters. In the following task, various level of access are configured for users. After Step 2 is performed for a new device, all the steps are optional.
  1. Enter global configuration mode.
    device# configure terminal
  2. Create a user with the desired privilege level. On the same line, create a password.
    Note: The colon character is not allowed in usernames.
    • privilege 0 - Super-user (default) allows complete read-and-write access to the system.
    • privilege 4 - Read-and-write access for specific ports (but not for global parameters)
    • privilege 5 - Read-only access.
    Note: In FastIron 09.0.10a and later releases, both of the following command options create encrypted passwords (previously, the password option created an unencrypted password).
    • password
    • create-password
    device(config)# username super privilege 0 create-password xpassx
    device(config)#
  3. To prevent unauthorized user account deletion enter the service local-user-protection command.
    device(config)# service local-user-protection
    The service local-user-protection command applies to all user accounts. When you try to delete a specific user you will be prompted for verification before deleting that user.
  4. (Optional) Display user account information using the show users command.

The following example creates a user account with read/write access and an encrypted password using the create-password command.

device(config)# username user-mktg3 privilege 0 create-password xpassx

The following example creates a user with read-only privileges.

ICX7550-24P Router(config)# username read_user privilege 5 pass
  password          Specify the password for the user
ICX7550-24P Router(config)# username read_user privilege 5 password read_user
ICX7550-24P Router(config)# show user
Username                                        Password                           Encrypt   Priv Status   Expire Time
======================================================================================================================
super                                           $1$M78fhauw$Pk4tQyYlhe722GG7WG2wZ  enabled   0    enabled  Never
read_user                                       $1$M78fhauw$8F.GCXRWk3mAVW/OxA3HB  enabled   5    enabled  Never