Login Security
After the user logs in the UCM6200 Web GUI, the user will be automatically logged out after certain timeout, or
he/she can be banned for a specific period if the login timeout is exceeded. Those values can be specified under
UCM6200 web GUI→Maintenance→Login Settings→Login security page.
The “User Login Timeout” value is in minute and the default setting is 10 minutes. If the user does not make
any operation on Web GUI before the timeout, the user will be logged out automatically. After that, the Web
GUI will be redirected to the login page and the user will need to enter the username and password again to
log back in.
If set to 0, there will be no timeout period, and users can remain logged in for an indefinite period of time.
“Maximum number of login attempts” protects the UCM against brute force authentication attempts. If the
number of attempts from an IP address exceeds the configured value, it will be blacklisted, and the IP address
will be banned based on the configured User ban period. Default value is 5.
“User ban period” specifies the amount of time (in minutes) that an IP address is banned from attempting to
log into the UCM system. A value of 0 indicates a permanent ban. Default value is 5.
“Login Banned User List” shows the list of IP addresses banned from the UCM.
“Login Whitelist” Users can create a list of IP addresses that will not be banned even if they exceed the
maximum number of failed login attempts.