
Chapter 25 User/Group
ZyWALL (ZLD) CLI Reference Guide
239
25.2.4.2 Force Authentication Policy Insert Command Example
The following commands show how to insert a force authentication policy at position 1 of the
checking order. This policy applies endpoint secruity policies and uses the following settings:
• Activate: yes
• Description: EPS-on-LAN
• Source: use address object “LAN1_SUBNET”
• Destination: use address object “DMZ_Servers”
• User Authentication: required
• Schedule: no specified
• Endpoint security: Activate
• endpoint security object: use “EPS-WinXP” and “EPS-WinVista” for the first and second
checking EPS objects
25.2.5 Additional User Commands
This table lists additional commands for users.
[no] schedule schedule_name Sets the time criteria for the specified condition.
The
no command removes the time criteria,
making the condition effective all the time.
[no] source {address_object | group_name} Sets the source criteria for the specified condition.
The no command removes the source criteria,
making the condition effective for all sources.
show Displays information about the specified condition.
Table 134 force-auth policy Sub-commands (continued)
COMMAND DESCRIPTION
Router# configure terminal
Router(config)# force-auth policy insert 1
Router(config-force-auth-1)# activate
Router(config-force-auth-1)# description EPS-on-LAN
Router(config-force-auth-1)# source LAN1_SUBNET
Router(config-force-auth-1)# destination DMZ_Servers
Router(config-force-auth-1)# authentication force
Router(config-force-auth-1)# no schedule
Router(config-force-auth-1)# eps activate
Router(config-force-auth-1)# eps 1 EPS-WinXP
Router(config-force-auth-1)# eps 2 EPS-WinVista
Router(config-force-auth-1)# exit
Table 135 username/groupname Commands Summary: Additional
COMMAND DESCRIPTION
show users {username | all | current} Displays information about the users logged onto
the system.
show lockout-users Displays users who are currently locked out.
unlock lockout-users ip | console Unlocks the specified IP address.
users force-logout ip | username Logs out the specified logins.
Komentáře k této Příručce