19 
Step Command Remarks 
6.  Set the maximum number of 
concurrent users of the local 
user account. 
access-limit max-user-number 
Optional. 
By default, there is no limit to the 
maximum number of concurrent 
users of a local user account. 
The limit is effective only for local 
accounting, and is not effective for 
FTP users. 
7.  Configure the password 
control attributes for the local 
user. 
•  Set the password aging time: 
password-control aging 
aging-time 
•  Set the minimum password 
length: 
password-control length length
•  Configure the password 
composition policy: 
password-control composition 
type-number type-number 
[ type-length type-length ] 
Optional. 
By default, the local user uses 
password control attributes of the 
user group to which the local user 
belongs, and uses the global 
setting for any password control 
attribute that is not configured in 
the user group. 
For more information about 
password control configuration 
commands, see Security 
Command Reference. 
8.  Configure the binding 
attributes for the local user. 
bind-attribute { ip ip-address | 
location port slot-number 
subslot-number port-number | mac 
mac-address | vlan vlan-id } * 
Optional. 
By default, no binding attribute is 
configured for a local user. 
9.  Configure the authorization 
attributes for the local user. 
authorization-attribute { acl 
acl-number | idle-cut minute | level 
level | user-profile profile-name | 
user-role { guest | guest-manager 
| security-audit } | vlan vlan-id | 
work-directory directory-name } *
Optional. 
By default, no authorization 
attribute is configured for a local 
user. 
For LAN and portal users, only acl, 
idle-cut, user-profile, and vlan are 
supported.  
For SSH, terminal, and Web users, 
only level is supported. 
For FTP users, only level and 
work-directory are supported. 
For Telnet users, only level and 
user-role is supported.  
For other types of local users, no 
binding attribute is supported. 
10.  Set the validity time of the 
local user. 
validity-date time 
Optional. 
Not set by default. 
11.  Set the expiration time of the 
local user. 
expiration-date time 
Optional. 
Not set by default. 
12.  Assign the local user to a user 
group. 
group group-name 
Optional. 
By default, a local user belongs to 
the default user group system.