EasyManuals Logo

Cisco ISR 4000 series User Manual

Cisco ISR 4000 series
66 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #16 background imageLoading...
Page #16 background image
Cisco ISR 4000 Family Routers Administrator Guidance
Page 16 of 66
When creating administrator accounts, all individual accounts are to be set to a privilege level of
one. This is done by using the following commands:
TOE-common-criteria(config)# username <name> password <password>
to create a new username and password combination, and
TOE-common-criteria(config)# username <name> privilege 1
to set the privilege level of <name> to 1.
3.2.5 Session Termination
Inactivity settings must trigger termination of the administrator session. These settings are
configurable by setting
TOE-common-criteria(config)# line vty <first> <last>
TOE-common-criteria(config-line)# exec-timeout <time>
TOE-common-criteria(config-line)# line console
TOE-common-criteria(config)# exec-timeout <time>
To save these configuration settings to the startup configuration:
copy run start
where first and last are the range of vty lines on the box (i.e. “0 4”), and time is the period of
inactivity after which the session should be terminated. Configuration of these settings is limited
to the privileged administrator (see Section 4.1).
The line console setting is not immediately activated for the current session. The current console
session must be exited. When the user logs back in, the inactivity timer will be activated for the
new session.
3.2.6 User Lockout
User accounts must be configured to lockout after a specified number of authentication failures
TOE-common-criteria(config)# aaa local authentication attempts max-fail [number of failures]
where number of failures is the number of consecutive failures that will trigger locking of the
account. Configuration of these settings is limited to the privileged administrator (see Section 4.1).
Related commands:
clear aaa local user fail-attempts
[username username | all]
Clears the unsuccessful login
attempts of the user.
clear aaa local user lockout
username [username]
Unlocks the locked-out user.
show aaa local user lockout
Displays a list of all locked-out
users.

Table of Contents

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Cisco ISR 4000 series and is the answer not in the manual?

Cisco ISR 4000 series Specifications

General IconGeneral
Routing PerformanceUp to 2 Gbps
Switching CapacityVaries by model
Operating SystemCisco IOS XE
DimensionsVaries by model
WeightVaries by model
SeriesISR 4000
WAN PortsVaries by model
LAN PortsVaries by model
RedundancyYes
TypeModular
Routing ThroughputUp to 2 Gbps
MemoryUp to 16 GB
Modular SlotsVaries by model
Power SupplyAC or DC options
Product FamilyISR (Integrated Services Router)
ModelsISR 4321, ISR 4331, ISR 4351, ISR 4431, ISR 4451-X
StorageSSD options
Network InterfacesGigabit Ethernet, SFP
Security FeaturesFirewall, VPN
Virtualization SupportYes
ModularityYes
Operating Temperature0 to 40°C
Humidity5% to 95% noncondensing

Related product manuals