To do…

Use the command…

Remarks

 

 

Optional

 

 

By default, the HTTPS service is not associated

 

 

with any certificate-based attribute access

 

 

control policy.

 

 

Associating the HTTPS service with a

 

 

certificate-based attribute access control

 

 

policy enables the device to control the

Associate the HTTPS service

 

access rights of clients.

ip https certificate

You must configure the client-verify enable

with a certificate

access-control-policy

command in the associated SSL server

attribute-based access control

policy-name

policy. If not, no clients can log in to the

policy

 

device.

 

 

 

 

The associated SSL server policy must

 

 

contain at least one permit rule.

 

 

Otherwise, no clients can log in to the

 

 

device.

 

 

For more information about certificate

 

 

attribute-based access control policies, see

 

 

the Security Configuration Guide.

 

 

 

Configure the port number of

ip https port port-number

Optional

the HTTPS service

443 by default.

 

 

 

 

 

 

Required

 

 

By default, the HTTPS service is not associated

Associate the HTTPS service

ip https acl acl-number

with any ACL.

with an ACL

Associating the HTTPS service with an ACL

 

 

 

 

 

enables the device to allow only clients

 

 

permitted by the ACL to access the device.

 

 

 

Create a local user and enter

local-user user-name

Required

local user view

By default, no local user is configured.

 

 

 

 

Configure a password for the

password { cipher simple }

Required

By default, no password is configured for the

local user

password

local user.

 

 

 

 

 

Specify the command level of

authorization-attribute level

Required

By default, no command level is configured for

the local user

level

the local user.

 

 

 

 

 

Specify the Telnet service type

 

Required

service-type telnet

By default, no service type is configured for

for the local user

 

the local user.

 

 

 

 

 

Exit to system view

quit

 

 

 

Create a VLAN interface and

interface vlan-interface

Required

If the VLAN interface already exists, the

enter its view

vlan-interface-id

command enters its view.

 

 

 

 

 

Assign an IP address and

ip address ip-address { mask

Required

subnet mask to the VLAN

By default, no IP address is assigned to the

mask-length }

interface

VLAN interface.

 

 

 

 

 

69