< Home

display remote-user authen-fail

Function

The display remote-user authen-fail command displays the accounts that fail in remote AAA authentication.

Format

display remote-user authen-fail [ blocked | username username ]

Parameters

Parameter

Description

Value

blocked

Displays all the remote AAA authentication accounts that have been locked.

-

username username

Displays details about the accounts that fail in remote AAA authentication.

If the username parameter is not specified, basic information about all accounts that fail in remote AAA authentication is displayed.

It is a string of 1 to 253 case-insensitive characters without spaces.

Views

All views

Default Level

3: Management level

Usage Guidelines

Usage Scenario

After the account locking function is enabled for the users who fail in AAA remote authentication, the device records all failed accounts, including:
  • The accounts that failed in authentication and are locked, for example, when the user entered the wrong account name or password too many times.
  • The accounts that failed in authentication, but are not locked, for example, when the number of times the account name or password was entered incorrectly did not exceed the limit.

Prerequisites

The access-user remote authen-fail command has been executed to enable the account locking function for access users who fail remote authentication. Alternatively, the administrator remote authen-fail command has been executed to enable the account locking function for administrators who fail remote authentication.

Precautions

The device cannot back up a recorded account that fails the AAA authentication. If an active/standby switchover policy has been configured on the device, all user entries are cleared when the device completes an active/standby switchover.

Example

# Display all accounts that have failed in remote AAA authentication.

<HUAWEI> display remote-user authen-fail
  Interval: Retry Interval(Mins)
  TimeLeft: Retry Time Left
  BlockDuration: Block Duration(Mins)
  -------------------------------------------------------------------------------------------
  Username                   Interval  TimeLeft  BlockDuration  UserType
  -------------------------------------------------------------------------------------------
  www@test                   0         0         65414          administrator
  -------------------------------------------------------------------------------------------
  Total 1, 1 printed

# Display all locked accounts.

<HUAWEI> display remote-user authen-fail blocked
Interval: Retry Interval(Mins)
TimeLeft: Retry Time Left
BlockDuration: Block Duration(Mins)
---------------------------------------------------------------------------------------------------------
Username                   Interval  TimeLeft  BlockDuration  BlockTime                 UserType
---------------------------------------------------------------------------------------------------------
www@test                   0         0         65414          2018-04-23 17:22:09+08:00 administrator
---------------------------------------------------------------------------------------------------------
Total 1, 1 printed

# Display details about the account test that failed in remote AAA authentication.

<HUAWEI> display remote-user authen-fail username test
  The contents of the user:
  User-type             : Administrator
  Retry interval(Mins)  : 29
  Retry time left       : 4
  Block time left(Mins) : 0
  User state            : Block
Table 1 Description of the display remote-user authen-fail command output

Item

Description

Username

User name.

Interval or Retry interval(Mins)

Authentication retry interval, in minutes.

To configure this parameter, run the access-user remote authen-fail or administrator remote authen-failcommand.

TimeLeft or Retry Time Left

Remaining number of consecutive authentication failures.

To configure this parameter, run the access-user remote authen-fail or administrator remote authen-failcommand.

BlockDuration or Block time left(Mins)

User account locking duration, in minutes.

To configure this parameter, run the access-user remote authen-fail or administrator remote authen-failcommand.

UserType

User type:

  • administrator
  • access-user

BlockTime

User account locking time.

Block-time-left

Remaining locking time of an account.

User-state

User status:
  • Block
  • Active
Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
< Previous topic Next topic >