26
• Scheme—Uses the AAA module to provide local or remote console login authentication. You must
provide a username and password for accessing the CLI. If the username or password configured
on a remote server was lost, contact the server administrator for help.
By default, console login does not require authentication. Any user can log in through the console port
without authentication and have user privilege level 3. To improve device security, configure the
password or scheme authentication mode immediately after you log in to the device for the first time.
Table 13 Configuration required for different console login authentication modes
Authentication
mode
Configuration tasks Reference
None
Set the authentication mode to none for the AUX user
interface.
"Disable authentication for
console login (not supported
in FIPS mode)"
Password
Enable password authentication on the AUX user
interface.
Set a password.
"Configuring password
authentication for console
login (not supported in FIPS
mode)"
Scheme
Enable scheme authentication on the AUX user interface.
Configure local or remote authentication settings.
To configure local authentication:
1. Configure a local user and specify the password.
2. Configure the device to use local authentication.
To configure remote authentication:
1. Configure the RADIUS or HWTACACS scheme on
the device.
2. Configure the username and password on the AAA
server.
3. Configure the device to use the scheme for user
authentication.
"Configuring scheme
authentication f
or console
login"
Disable authentication for console login (not supported in FIPS
mode)
Step Command Remarks
1. Enter system view.
system-view N/A
2. Enter AUX user interface view.
user-interface aux first-number
[ last-number ]
N/A
3. Disable authentication.
authentication-mode none
By default, you can log in to the
device through the console port
without authentication and have
user privilege level 3.
4. Configure common settings
for console login.
See "Configuring common console
login settings (
optional)."
Optional.