HP VPN Firewall Appliances Getting Started Guide
110
Ste
p
Command
Remarks
3. Configure the password
for the user privilege
level.
super password [ level
user-level ] { cipher |
simple } password
If local authentication is involved, this step is
required.
By default, a privilege level has no password.
If no user privilege level is specified when you
configure the command, the user privilege
level defaults to 3.
If local-only authentication is used, a console user interface user can switch to a higher privilege level,
even if the privilege level has not been assigned a password.
Switching to a higher user privilege level
Before you switch to a higher user privilege level, obtain the required authentication data as described
in Table 19.
If the switching mode is
local, the privilege level switching fails after three consecutive incorrect password
attempts. If the switching mode is scheme, the privilege level switching fails after five consecutive
incorrect password attempts.
In the local switching mode, if the authentication mode of the user interface is scheme, the user is locked
for 15 minutes after five consecutive incorrect password attempts. Within the lock interval, the user cannot
switch to a higher privilege level. The lock timer restarts when the user makes a new password attempt
within the lock interval.
To switch the user privilege level, perform the following task in user view:
Task Command Remarks
Switch the user
privilege level.
super [ level ]
When logging in to the device, a user has a user privilege level,
which depends on user interface or authentication user level.
Table 19 Information required for user privilege level switching
User interface
authentication
mode
User privilege
level switching
authentication
mode
Information required for the
first authentication mode
Information required for the
second authentication mode
none/password
local
Password configured for the
privilege level on the device with
the super password command.
N/A
local scheme
Password configured for the
privilege level on the device with
the super password command.
Username and password
configured on the AAA server for
the privilege level.
scheme
Username and password for the
privilege level.
N/A
scheme local
Username and password for the
privilege level.
Local user privilege level
switching password.