Command Line Interface Guide
Page 72
Configures the interval that the system waits until user input is the "port default VLAN ID (PVID)". Configures the baud rate of the specified VLAN, and the VLAN ID is detected. MA (Management Access-level) Mode...Exits the MST region configuration mode without applying configuration changes. LC (Line Configuration) Mode Command Group autobaud enable authentication exec-timeout history history size login authentication password password-aging speed Description Configures the line for a particular line. Exits the MST region configuration mode and applies all configuration changes....
Configures the interval that the system waits until user input is the "port default VLAN ID (PVID)". Configures the baud rate of the specified VLAN, and the VLAN ID is detected. MA (Management Access-level) Mode...Exits the MST region configuration mode without applying configuration changes. LC (Line Configuration) Mode Command Group autobaud enable authentication exec-timeout history history size login authentication password password-aging speed Description Configures the line for a particular line. Exits the MST region configuration mode and applies all configuration changes....
Command Line Interface Guide
Page 81
... Mode Global Configuration mode. Uses the list of this argument as the command aaa authentication login default local. AAA Commands aaa authentication login The aaa authentication login Global Configuration mode command defines login authentication. This has the same effect as the default list of all RADIUS servers for authentication. Specify at least one from the following...
... Mode Global Configuration mode. Uses the list of this argument as the command aaa authentication login default local. AAA Commands aaa authentication login The aaa authentication login Global Configuration mode command defines login authentication. This has the same effect as the default list of all RADIUS servers for authentication. Specify at least one from the following...
Command Line Interface Guide
Page 82
... higher privilege levels. (Range: 1 - 12 characters) • method1 [method2...] - User Guidelines • The default and optional list names created with the aaa authentication login command are used to name the list of authentication methods activated, when using higher privilege levels. • list-name ...line. If the RADIUS server is not available, authentication is any character string used to the default configuration. The method argument identifies the list of authentication are used with the login authentication command. • Create a list by entering the aaa authentication...
... higher privilege levels. (Range: 1 - 12 characters) • method1 [method2...] - User Guidelines • The default and optional list names created with the aaa authentication login command are used to name the list of authentication methods activated, when using higher privilege levels. • list-name ...line. If the RADIUS server is not available, authentication is any character string used to the default configuration. The method argument identifies the list of authentication are used with the login authentication command. • Create a list by entering the aaa authentication...
Command Line Interface Guide
Page 83
... is not set , the process still succeeds. Console(config)# aaa authentication enable default enable login authentication The login authentication Line Configuration mode command specifies the login authentication method list for authentication when accessing higher privilege levels. where x is checked. ...in the command line. • All aaa authentication enable default requests sent by the device to the default configuration specified by the aaa authentication login command. User Guidelines • The default and optional list names created with the aaa authentication enable command...
... is not set , the process still succeeds. Console(config)# aaa authentication enable default enable login authentication The login authentication Line Configuration mode command specifies the login authentication method list for authentication when accessing higher privilege levels. where x is checked. ...in the command line. • All aaa authentication enable default requests sent by the device to the default configuration specified by the aaa authentication login command. User Guidelines • The default and optional list names created with the aaa authentication enable command...
Command Line Interface Guide
Page 84
... authentication method list when accessing a higher privilege level from default to the default configuration specified by the aaa authentication enable command. Uses the default list created with the command aaa authentication login. Command Mode Line Configuration mode. Use the no login authentication • default - Syntax • login authentication {default | list-name} • no form of this command to...
... authentication method list when accessing a higher privilege level from default to the default configuration specified by the aaa authentication enable command. Uses the default list created with the command aaa authentication login. Command Mode Line Configuration mode. Use the no login authentication • default - Syntax • login authentication {default | list-name} • no form of this command to...
Command Line Interface Guide
Page 87
Command Mode Privileged EXEC mode. User Guidelines There are no default configuration. Example The following example displays the authentication configuration. Syntax • show authentication methods Privileged EXEC mode command displays information about the authentication methods. Console# sh authentication methods Login Authentication Method Lists Console_Default: None Network_Default: Local Enable Authentication Method Lists Console_Default: Enable...
Command Mode Privileged EXEC mode. User Guidelines There are no default configuration. Example The following example displays the authentication configuration. Syntax • show authentication methods Privileged EXEC mode command displays information about the authentication methods. Console# sh authentication methods Login Authentication Method Lists Console_Default: None Network_Default: Local Enable Authentication Method Lists Console_Default: Enable...
Command Line Interface Guide
Page 88
... password is 32 characters. Example The following example specifies password secret on a line. Encrypted password to remove the password. Line Console Telnet SSH Login Method List Default Default Default Enable Method List Default Default Default http https dot1x console# : Local : Local : password The password Line Configuration mode command specifies a password on a console. Use the no password •...
... password is 32 characters. Example The following example specifies password secret on a line. Encrypted password to remove the password. Line Console Telnet SSH Login Method List Default Default Default Enable Method List Default Default Default http https dot1x console# : Local : Local : password The password Line Configuration mode command specifies a password on a console. Use the no password •...
Command Line Interface Guide
Page 267
... variable. The message must start in a new line and can be a multi-line message. Delimiting character, for example a pound sign (#). Message text. Default Configuration Disabled (no banner exec • d - Syntax • banner exec d message d • no EXEC banner is displayed. Tokens in the... form $(token) in the message text can be included. Command Mode Global Configuration mode. Login Banner banner exec The banner exec Global Configuration mode command specifies and enables a message to be used in the banner message. • message...
... variable. The message must start in a new line and can be a multi-line message. Delimiting character, for example a pound sign (#). Message text. Default Configuration Disabled (no banner exec • d - Syntax • banner exec d message d • no EXEC banner is displayed. Tokens in the... form $(token) in the message text can be included. Command Mode Global Configuration mode. Login Banner banner exec The banner exec Global Configuration mode command specifies and enables a message to be used in the banner message. • message...
Command Line Interface Guide
Page 269
... mode command specifies and enables a message to the device, the EXEC banner is displayed). Syntax • banner login d message d • no Login banner is displayed. Tokens in the form $(token) in the message text can be a multi-line message. ... Delimiting character, for example a pound sign (#). Tokens are described in to be included. Login Banner 269 Default Configuration Disabled (no banner login • d - User Guidelines • Follow this command to delete the existing Login banner. The message must start in the banner message. • message - Use the ...
... mode command specifies and enables a message to the device, the EXEC banner is displayed). Syntax • banner login d message d • no Login banner is displayed. Tokens in the form $(token) in the message text can be a multi-line message. ... Delimiting character, for example a pound sign (#). Tokens are described in to be included. Login Banner 269 Default Configuration Disabled (no banner login • d - User Guidelines • Follow this command to delete the existing Login banner. The message must start in the banner message. • message - Use the ...
Command Line Interface Guide
Page 271
... configuration variable. After the user logs in to a device, the message-of-the-day (MOTD) banner appears first, followed by the login banner and prompts. Use the no form of -the-day banner. Syntax • banner motd d message d • no MOTD banner... is displayed. Tokens are described in the banner message. • message - A delimiting character cannot be included. Default Configuration Disabled (no banner motd • d - banner motd The banner motd Global Configuration mode command specifies and enables a message-of this command with...
... configuration variable. After the user logs in to a device, the message-of-the-day (MOTD) banner appears first, followed by the login banner and prompts. Use the no form of -the-day banner. Syntax • banner motd d message d • no MOTD banner... is displayed. Tokens are described in the banner message. • message - A delimiting character cannot be included. Default Configuration Disabled (no banner motd • d - banner motd The banner motd Global Configuration mode command specifies and enables a message-of this command with...
Command Line Interface Guide
Page 273
Command Mode Line Configuration mode. Syntax • exec-banner • no exec-banner Default Configuration Enabled Command Mode Line Configuration mode User Guidelines There are no form of this command to disable the display of this command. Syntax • login-banner • no form of exec banners. Example The following example enables the...
Command Mode Line Configuration mode. Syntax • exec-banner • no exec-banner Default Configuration Enabled Command Mode Line Configuration mode User Guidelines There are no form of this command to disable the display of this command. Syntax • login-banner • no form of exec banners. Example The following example enables the...
Command Line Interface Guide
Page 274
...User Guidelines There are no motd-banner Default Configuration Enabled Command Mode Line Configuration mode. Example The following example enables the display of motd banners. User Guidelines There are no form of this command to disable the display of login banners. Syntax • motd-banner ...-of -the-day banners. Console# Console (config)# line console Console(config-line)# motd-banner 274 Login Banner Console# Console (config)# line console Console(config-line)# login-banner motd-banner The motd-banner Line Configuration mode command enables the display of message-of -the-day...
...User Guidelines There are no motd-banner Default Configuration Enabled Command Mode Line Configuration mode. Example The following example enables the display of motd banners. User Guidelines There are no form of this command to disable the display of login banners. Syntax • motd-banner ...-of -the-day banners. Console# Console (config)# line console Console(config-line)# motd-banner 274 Login Banner Console# Console (config)# line console Console(config-line)# login-banner motd-banner The motd-banner Line Configuration mode command enables the display of message-of -the-day...
Command Line Interface Guide
Page 275
User Guidelines There are no default configuration. Device> show banner exec Default Configuration This command has no user guidelines for this command. Example The following example displays the banners configuration. Syntax • show banner motd • show banner login • show motd Console: Enabled Telnet: Enabled SSH: Enabled MOTD Message $(bold)Upgrade$(bold) to all devices begins at March 12 Login Banner 275 Command Mode Privileged EXEC mode. show banner The show banner Privileged EXEC mode command displays the banners configuration.
User Guidelines There are no default configuration. Device> show banner exec Default Configuration This command has no user guidelines for this command. Example The following example displays the banners configuration. Syntax • show banner motd • show banner login • show motd Console: Enabled Telnet: Enabled SSH: Enabled MOTD Message $(bold)Upgrade$(bold) to all devices begins at March 12 Login Banner 275 Command Mode Privileged EXEC mode. show banner The show banner Privileged EXEC mode command displays the banners configuration.
Command Line Interface Guide
Page 407
...to disable logging file system events. User Guidelines Other types of this command to this command to successful login events, unsuccessful login events and other login-related events. Example The following example clears messages from the logging file. aaa logging The aaa logging... Global Configuration mode command enables logging AAA login events in the syslog. Default Configuration Logging AAA login events is enabled. Console(config)# aaa logging login file-system logging The file-system logging Global Configuration mode command enables logging ...
...to disable logging file system events. User Guidelines Other types of this command to this command to successful login events, unsuccessful login events and other login-related events. Example The following example clears messages from the logging file. aaa logging The aaa logging... Global Configuration mode command enables logging AAA login events in the syslog. Default Configuration Logging AAA login events is enabled. Console(config)# aaa logging login file-system logging The file-system logging Global Configuration mode command enables logging ...
Command Line Interface Guide
Page 411
.... Messages: 6 Dropped (severity). User Guidelines There are no default configuration. Console logging: level debugging. Messages: 6 Dropped (severity). 2 messages were not logged (resources) Application filtering control Application Event Status AAA Login Enabled Syslog Commands 411 Syslog server 192.180.2.27 logging: errors..., 200 Max. show logging file The show logging file Logging is enabled. Syntax • show logging file Default Configuration This command has no user guidelines for this command. Example The following example displays the logging state and ...
.... Messages: 6 Dropped (severity). User Guidelines There are no default configuration. Console logging: level debugging. Messages: 6 Dropped (severity). 2 messages were not logged (resources) Application filtering control Application Event Status AAA Login Enabled Syslog Commands 411 Syslog server 192.180.2.27 logging: errors..., 200 Max. show logging file The show logging file Logging is enabled. Syntax • show logging file Default Configuration This command has no user guidelines for this command. Example The following example displays the logging state and ...
Command Line Interface Guide
Page 442
... the password is defined (not from the day the aging is defined). • After a password expires a user can login for another 3 times. • 10 days before a password change is forced. (Range: 1 - 365) Default Configuration Password aging is generated. Use the no form of line passwords. Command Mode Line Configuration mode. Example The...
... the password is defined (not from the day the aging is defined). • After a password expires a user can login for another 3 times. • 10 days before a password change is forced. (Range: 1 - 365) Default Configuration Password aging is generated. Use the no form of line passwords. Command Mode Line Configuration mode. Example The...
Command Line Interface Guide
Page 443
...the local database can be reused. (Range: 1 - 10) TIC Commands 443 Indicates the required number of required password changes before a password can login for which the password applies. (Range: 1 - 15) • days - Command Mode Global Configuration mode. The level for another 3 times.... • 10 days before a password change is forced. (Range: 1 - 365) Default Configuration Password aging is calculated from the day the password was defined, and not from the day the aging was defined. • After a password ...
...the local database can be reused. (Range: 1 - 10) TIC Commands 443 Indicates the required number of required password changes before a password can login for which the password applies. (Range: 1 - 15) • days - Command Mode Global Configuration mode. The level for another 3 times.... • 10 days before a password change is forced. (Range: 1 - 365) Default Configuration Password aging is calculated from the day the password was defined, and not from the day the aging was defined. • After a password ...
Command Line Interface Guide
Page 445
...'irrelevant'. Example The following example configures the number of days, it may cause the irrelevant password to 120. Number of failed login attempts before the user account is locked. Console(config)# passwords lockout 3 TIC Commands 445 User Guidelines • Relevant to local... hold-time 120 passwords lockout The passwords lockout Global Configuration mode command sets the number of failed login attempts before a user account is locked. (Range: 1 - 5) Default Configuration No locked user account due to remove this condition. Use the no passwords lockout • number ...
...'irrelevant'. Example The following example configures the number of days, it may cause the irrelevant password to 120. Number of failed login attempts before the user account is locked. Console(config)# passwords lockout 3 TIC Commands 445 User Guidelines • Relevant to local... hold-time 120 passwords lockout The passwords lockout Global Configuration mode command sets the number of failed login attempts before a user account is locked. (Range: 1 - 5) Default Configuration No locked user account due to remove this condition. Use the no passwords lockout • number ...
Command Line Interface Guide
Page 446
... of this command to disable writing to the login history file. Use the no form of the user. (Range: 1 - 20 characters) Default Configuration This command has no aaa login-history file Default Configuration Writing to the login history file. Command Mode Global Configuration mode. ...command reactivates a locked user account. Syntax • aaa login-history file • no default configuration. User Guidelines The login history is enabled. Command Mode Privileged EXEC mode. aaa login-history file The aaa login-history file Global Configuration mode command enables writing to the ...
... of this command to disable writing to the login history file. Use the no form of the user. (Range: 1 - 20 characters) Default Configuration This command has no aaa login-history file Default Configuration Writing to the login history file. Command Mode Global Configuration mode. ...command reactivates a locked user account. Syntax • aaa login-history file • no default configuration. User Guidelines The login history is enabled. Command Mode Privileged EXEC mode. aaa login-history file The aaa login-history file Global Configuration mode command enables writing to the ...
Command Line Interface Guide
Page 450
... guidelines for this command. User Guidelines There are no default configuration. show users login-history The show users login-history [username name] • name - Syntax • show users login-history Privileged EXEC mode command displays information about the login history of users. Console# show users login-history Login Time Jan 18 2004 23:58:17 Jan 19...
... guidelines for this command. User Guidelines There are no default configuration. show users login-history The show users login-history [username name] • name - Syntax • show users login-history Privileged EXEC mode command displays information about the login history of users. Console# show users login-history Login Time Jan 18 2004 23:58:17 Jan 19...