User Accounts Overview
You can create accounts for local users with or without passwords. Accounts with passwords can have encrypted or unencrypted passwords. You can assign privilege levels to local user accounts, but on a new device, you must first create a local user account that has a Super User privilege before you can create accounts with other privilege levels.
User accounts regulate access to the management functions in the CLI using the following methods:
- Telnet access
- Web management access
- SNMP access
- SSH access─SSH refers to SSHv2 which is supported on all RUCKUS ICX devices.
For each local user account, you specify a user name. You also can specify the following parameters:
- A password
Note: If you use AAA authentication for SNMP access and set the password to be the same as the username, providing the password during authentication is optional. You can provide just the correct username for successful authentication.
- A management privilege level, which can be one of the following:
- 0 - Super User level (default) - Allows complete read-and-write access to the system. This is generally for system administrators and is the only privilege level that allows you to configure passwords.
- 4 - Port Configuration level - Allows read-and-write access for specific ports, but not for global parameters.
- 5 - Read Only level - Allows access to the Privileged EXEC mode and User EXEC mode with read access only.
Local user accounts provide greater flexibility for controlling management access to RUCKUS devices than do management privilege level passwords and SNMP community strings of SNMP versions 1 and 2. You can continue to use the privilege level passwords and the SNMP community strings as additional means of access authentication. Alternatively, you can choose not to use local user accounts and instead continue to use only the privilege level passwords and SNMP community strings. Local user accounts are backward-compatible with configuration files that contain privilege level passwords.
User Account Guidelines
Be aware of the following guidelines for user accounts.
- If a message of the day (MOTD) is configured, the user is required to press the Enter
key before logging in. The MOTD is configured using the
banner motdcommand. Unless configured, the requirement to accept the MOTD is disabled by default. - Users are locked out (disabled) if they fail to login after three attempts. This
feature is automatically enabled. Use the
disable-on-login-failurecommand to change the number of login attempts (up to 10) before users are locked out.