27

User/Group

27.1 Overview

This chapter describes how to set up user accounts, user groups, and user settings for the ZyWALL. You can also set up rules that control when users have to log in to the ZyWALL before the ZyWALL routes traffic for them.

27.1.1What You Can Do in this Chapter

The User screen (see Section 27.2 on page 373) provides a summary of all user accounts.

The Group screen (see Section 27.3 on page 376) provides a summary of all user groups. In addition, this screen allows you to add, edit, and remove user groups. User groups may consist of access users and other user groups. You cannot put admin users in user groups

The Setting screen (see Section 27.4 on page 378) controls default settings, login settings, lockout settings, and other user settings for the ZyWALL. You can also use this screen to specify when users must log in to the ZyWALL before it routes traffic for them.

27.1.2What You Need To Know

User Account

A user account defines the privileges of a user logged into the ZyWALL. User accounts are used in firewall rules, in addition to controlling access to configuration and services in the ZyWALL.

User Types

These are the types of user accounts the ZyWALL uses.

Table 132 Types of User Accounts

TYPE

ABILITIESLOGIN METHOD(S)

Admin Users

 

 

 

 

 

admin

Change ZyWALL configuration (web, CLI)

WWW, TELNET, SSH, FTP, Console

 

 

 

limited-admin

Look at ZyWALL configuration (web, CLI)

WWW, TELNET, SSH, Console

 

Perform basic diagnostics (CLI)

 

 

 

 

Access Users

 

 

 

 

 

user

Access network services

WWW, TELNET, SSH

 

Browse user-mode commands (CLI)

 

 

 

 

guest

Access network services

WWW

 

 

 

ext-user

External user account

WWW

 

 

 

ext-group-user

External group user account

WWW

 

 

 

 

371

ZyWALL 110/310/1100 Series User’s Guide