Version: latest 1.1.0 1.0.1 0.9.3
Location in GUI: Admin » AAA » Authentication » AAA
Name Type Constraint Mandatory Default Value remote_user_login_policy Choice assign-default-role, no-loginNo no-logindefault_fallback_check Boolean true, falseNo falsedefault_realm Choice local, tacacs, ldap, radiusNo localdefault_login_domain String Regex: ^[a-zA-Z0-9_.:-]{1,64}$ No console_realm Choice local, tacacs, ldap, radiusNo localconsole_login_domain String Regex: ^[a-zA-Z0-9_.:-]{1,64}$ No management_settings Class [management_settings]No security_domains List [security_domains]No
Name Type Constraint Mandatory Default Value password_strength_check Boolean true, falseNo falsepassword_strength_profile Class [password_strength_profile]No password_change_during_interval Boolean true, falseNo truepassword_change_count Integer min: 0, max: 10 No 2password_change_interval Integer min: 0, max: 745 No 48password_no_change_interval Integer min: 0, max: 745 No 24password_history_count Integer min: 0, max: 15 No 5web_token_timeout Integer min: 300, max: 9600 No 600web_token_max_validity Integer min: 4, max: 24 No 24web_session_idle_timeout Integer min: 60, max: 65525 No 1200include_refresh_session_records Boolean true, falseNo trueenable_login_block Boolean true, falseNo falselogin_block_duration Integer min: 1, max: 1440 No 60login_max_failed_attempts Integer min: 1, max: 15 No 5login_max_failed_attempts_window Integer min: 1, max: 720 No 5
Name Type Constraint Mandatory Default Value name String Regex: ^[a-zA-Z0-9_.:-]{1,64}$ Yes description String Regex: ^[a-zA-Z0-9\\!#$%()*,-./:;@ _{|}~?&+]{1,128}$ No restricted_rbac_domain Boolean true, falseNo false
Name Type Constraint Mandatory Default Value password_mininum_length Integer min: 8, max: 64 No 8password_maximum_length Integer min: 8, max: 64 No 64password_strength_test_type Choice default, customNo defaultpassword_class_flags List Choice[digits, lowercase, specialchars, uppercase] No
Example 1: In this example we set the default authentication method for GUI and console to radius with the login_domain created using both of our configured radius servers.
default_login_domain : yourDomainRadius
console_login_domain : yourDomainRadius
Example 2: In this example we set the default authentication method for GUI and console to tacacs with the login_domain created using both of our configured tacacs servers.
default_login_domain : yourDomainTacacs
console_login_domain : yourDomainTacacs
Example 3: In this example we set the default authentication method for GUI and console to local, where the local realm represents locally created users.
default_login_domain : local
console_login_domain : local
Example 4: In this example below we have created a security domain called secDomain1 where restricted RBAC has been enabled. Also in the management_settings we enable strong password check for local passwords, where they need to be of minimum length 8 and maximum length of 64 and needs to consist of lower case and uppercase characters.
restricted_rbac_domain : true
password_strength_check : true
password_strength_profile :
password_mininum_length : 8
password_maximum_length : 64
password_strength_test_type : custom
Example 5: In this example we defined the maximum lifetime of an authentication token to 24 hours using the web_token_max_validity setting. Where web_token_timeout defines a token will be marked invalid if not used after 600 seconds, where the web_session_idle_timeout defines to demand reauthentication after 1200 seconds for idle sessions on the web GUI.
web_token_max_validity : 24
web_session_idle_timeout : 1200
Location in GUI: Admin » AAA » Authentication » AAA
Name Type Constraint Mandatory Default Value remote_user_login_policy Choice assign-default-role, no-loginNo no-logindefault_fallback_check Boolean true, falseNo falsedefault_realm Choice local, tacacs, ldap, radiusNo localdefault_login_domain String Regex: ^[a-zA-Z0-9_.:-]{1,64}$ No console_realm Choice local, tacacs, ldap, radiusNo localconsole_login_domain String Regex: ^[a-zA-Z0-9_.:-]{1,64}$ No management_settings Class [management_settings]No security_domains List [security_domains]No
Name Type Constraint Mandatory Default Value password_strength_check Boolean true, falseNo falsepassword_strength_profile Class [password_strength_profile]No password_change_during_interval Boolean true, falseNo truepassword_change_count Integer min: 0, max: 10 No 2password_change_interval Integer min: 0, max: 745 No 48password_no_change_interval Integer min: 0, max: 745 No 24password_history_count Integer min: 0, max: 15 No 5web_token_timeout Integer min: 300, max: 9600 No 600web_token_max_validity Integer min: 4, max: 24 No 24web_session_idle_timeout Integer min: 60, max: 65525 No 1200include_refresh_session_records Boolean true, falseNo trueenable_login_block Boolean true, falseNo falselogin_block_duration Integer min: 1, max: 1440 No 60login_max_failed_attempts Integer min: 1, max: 15 No 5login_max_failed_attempts_window Integer min: 1, max: 720 No 5
Name Type Constraint Mandatory Default Value name String Regex: ^[a-zA-Z0-9_.:-]{1,64}$ Yes description String Regex: ^[a-zA-Z0-9\\!#$%()*,-./:;@ _{|}~?&+]{1,128}$ No restricted_rbac_domain Boolean true, falseNo false
Name Type Constraint Mandatory Default Value password_mininum_length Integer min: 8, max: 64 No 8password_maximum_length Integer min: 8, max: 64 No 64password_strength_test_type Choice default, customNo defaultpassword_class_flags List Choice[digits, lowercase, specialchars, uppercase] No
remote_user_login_policy : no-login
default_fallback_check : true
console_login_domain : tacacs
restricted_rbac_domain : true
password_strength_check : true
password_strength_profile :
password_mininum_length : 8
password_maximum_length : 64
password_strength_test_type : default
password_change_during_interval : true
password_change_interval : 48
password_no_change_interval : 24
password_history_count : 5
web_token_max_validity : 24
web_session_idle_timeout : 1200
include_refresh_session_records : true
enable_login_block : false
login_max_failed_attempts : 5
login_max_failed_attempts_window : 5
Location in GUI: Admin » AAA » Authentication » AAA
Name Type Constraint Mandatory Default Value remote_user_login_policy Choice assign-default-role, no-loginNo no-logindefault_fallback_check Boolean true, falseNo falsedefault_realm Choice local, tacacs, ldap, radiusNo localdefault_login_domain String Regex: ^[a-zA-Z0-9_.:-]{1,64}$ No console_realm Choice local, tacacs, ldap, radiusNo localconsole_login_domain String Regex: ^[a-zA-Z0-9_.:-]{1,64}$ No management_settings Class [management_settings]No security_domains List [security_domains]No
Name Type Constraint Mandatory Default Value password_strength_check Boolean true, falseNo falsepassword_strength_profile Class [password_strength_profile]No password_change_during_interval Boolean true, falseNo truepassword_change_count Integer min: 0, max: 10 No 2password_change_interval Integer min: 0, max: 745 No 48password_no_change_interval Integer min: 0, max: 745 No 24password_history_count Integer min: 0, max: 15 No 5web_token_timeout Integer min: 300, max: 9600 No 600web_token_max_validity Integer min: 4, max: 24 No 24web_session_idle_timeout Integer min: 600, max: 65525 No 1200include_refresh_session_records Boolean true, falseNo trueenable_login_block Boolean true, falseNo falselogin_block_duration Integer min: 1, max: 1440 No 60login_max_failed_attempts Integer min: 1, max: 15 No 5login_max_failed_attempts_window Integer min: 1, max: 720 No 5
Name Type Constraint Mandatory Default Value name String Regex: ^[a-zA-Z0-9_.:-]{1,64}$ Yes description String Regex: ^[a-zA-Z0-9\\!#$%()*,-./:;@ _{|}~?&+]{1,128}$ No restricted_rbac_domain Boolean true, falseNo false
Name Type Constraint Mandatory Default Value password_mininum_length Integer min: 8, max: 64 No 8password_maximum_length Integer min: 8, max: 64 No 64password_strength_test_type Choice default, customNo defaultpassword_class_flags List Choice[digits, lowercase, specialchars, uppercase] No
remote_user_login_policy : no-login
default_fallback_check : true
console_login_domain : tacacs
restricted_rbac_domain : true
password_strength_check : true
password_strength_profile :
password_mininum_length : 8
password_maximum_length : 64
password_strength_test_type : default
password_change_during_interval : true
password_change_interval : 48
password_no_change_interval : 24
password_history_count : 5
web_token_max_validity : 24
web_session_idle_timeout : 1200
include_refresh_session_records : true
enable_login_block : false
login_max_failed_attempts : 5
login_max_failed_attempts_window : 5
Location in GUI: Admin » AAA » Authentication » AAA
Name Type Constraint Mandatory Default Value remote_user_login_policy Choice assign-default-role, no-loginNo no-logindefault_fallback_check Boolean No falsedefault_realm Choice local, tacacs, ldap, radiusNo localdefault_login_domain String Regex: ^[a-zA-Z0-9_.:-]{1,64}$ No console_realm Choice local, tacacs, ldap, radiusNo localconsole_login_domain String Regex: ^[a-zA-Z0-9_.:-]{1,64}$ No management_settings Class [management_settings]No security_domains List [security_domains]No
Name Type Constraint Mandatory Default Value password_strength_check Boolean true, falseNo falsepassword_strength_profile Class [password_strength_profile]No password_change_during_interval Boolean true, falseNo truepassword_change_count Integer min: 0, max: 10 No 2password_change_interval Integer min: 0, max: 745 No 48password_no_change_interval Integer min: 0, max: 745 No 24password_history_count Integer min: 0, max: 15 No 5web_token_timeout Integer min: 300, max: 9600 No 600web_token_max_validity Integer min: 4, max: 24 No 24web_session_idle_timeout Integer min: 600, max: 65525 No 1200include_refresh_session_records Boolean true, falseNo trueenable_login_block Boolean true, falseNo falselogin_block_duration Integer min: 1, max: 1440 No 60login_max_failed_attempts Integer min: 1, max: 15 No 5login_max_failed_attempts_window Integer min: 1, max: 720 No 5
Name Type Constraint Mandatory Default Value name String Regex: ^[a-zA-Z0-9_.:-]{1,64}$ Yes description String Regex: ^[a-zA-Z0-9\\!#$%()*,-./:;@ _{|}~?&+]{1,128}$ No restricted_rbac_domain Boolean true, falseNo false
Name Type Constraint Mandatory Default Value password_mininum_length Integer min: 8, max: 64 No 8password_maximum_length Integer min: 8, max: 64 No 64password_strength_test_type Choice default, customNo defaultpassword_class_flags List Choice[digits, lowercase, specialchars, uppercase] No
remote_user_login_policy : no-login
default_fallback_check : true
console_login_domain : tacacs
restricted_rbac_domain : true
password_strength_check : true
password_strength_profile :
password_mininum_length : 8
password_maximum_length : 64
password_strength_test_type : default
password_change_during_interval : true
password_change_interval : 48
password_no_change_interval : 24
password_history_count : 5
web_token_max_validity : 24
web_session_idle_timeout : 1200
include_refresh_session_records : true
enable_login_block : false
login_max_failed_attempts : 5
login_max_failed_attempts_window : 5