Security Profile Mode Default Parameter Setting Changes

Some command parameter default settings change when changing the security profile mode. Security Profile Mode Command Parameter Default Setting Changes details command parameter default setting changes per security profile mode.

Click to expand in new window

Security Profile Mode Command Parameter Default Setting Changes

Description Command Normal Default C2 Default
Sets the time an idle console, SSH or Telnet CLI session will remain connected before being logged out. See Using the CLI for additional configuration information. set logout 10 minutes 15 minutes
Sets the number of minutes to lockout the default admin super-user account after maximum login attempts. See User Management Overview for additional configuration information. set system lockout time 0 minutes 8 minutes
Sets the minimum interval in minutes between password changes allowed for non-super-users. See User Management Overview for additional configuration information. set system password change-frequency 0 never 1 day
Sets the number of inactive days before a non-super-user account is locked out. See User Management Overview for additional configuration information. set system lockout inactive 0 never 90 days
Sets a grace period in either the number of logins or days before the password is locked out. See User Management Overview for additional configuration information. set system password grace-period logins 0 off 3 logins
Sets the number of days after a password expires before the password is locked out. See User Management Overview for additional configuration information. set system password grace-period time 0 off 30 days
Sets the SNMP user configuration privacy. set snmp user encryption usmNoPriv
Protocol usmAesCfg
128Protocol
Sets the SNMP user configuration authentication. set snmp user authentication usmNoAuth
Protocol usmHMACSHAAuthProtocol