
56
Ste
Command
Remarks
7. Associate the HTTPS
service with an ACL.
ip https acl acl-number
By default, the HTTPS service is not associated
with any ACL.
Associating the HTTPS service with an ACL
enables the device to allow only clients
permitted by the ACL to access the device.
8. Specify the authentication
mode for users trying to
log in to the device
through HTTPS.
web https-authorization
mode { auto | manual }
Optional.
By default, a user must enter the correct
username and password to log in through
HTTPS.
When the auto mode is enabled:
• If the user's PKI certificate is correct and not
expired, the CN field in the certificate is
used as the username to perform AAA
authentication. If the authentication
succeeds, the user automatically enters the
Web interface of the device.
• If the user's PKI certificate is correct and not
expired, but the AAA authentication fails,
the device shows the Web login page. The
user can log in to the device after entering
correct username and password.
9. Set the Web user
connection timeout time.
web idle-timeout minutes Optional.
10. Set the size of the buffer
for Web login logging.
web logbuffer size pieces Optional.
11. Create a local user and
enter local user view.
local-user user-name By default, a local user named admin exists.
12. Configure a password for
the local user.
password { cipher |
simple } password
By default, the password for system-predefined
user admin is admin, and no password is set
for any other local user.
13. Specify the command
level of the local user.
authorization-attribute
level level
By default, no command level is configured for
the local user.
14. Specify the Web service
type for the local user.
service-type web
By default, the system-predefined user admin
can use terminal service, Telnet service, SSH
service, and Web service, and no service type
is specified for any other local user.
15. Exit to system view.
quit N/A
16. Enter interface view.
interface interface-type
interface-number
N/A
17. Assign an IP address and
subnet mask to the
interface.
ip address ip-address
{ mask | mask-length }
N/A
By default, only interface GigabitEthernet 0/0
is assigned an IP address (192.168.0.1/24).
Komentarze do niniejszej Instrukcji