2-10To do… Use the command… RemarksSet the privilege level of theuser level levelOptionalBy default, the privilege level of the user is0.Configure the authorizedVLAN for the local user authorization vlan stringRequiredBy default, no authorized VLAN isconfigured for the local user.Set the attributes of the userwhose service type islan-accessattribute { ip ip-address | macmac-address | idle-cut second |access-limit max-user-number |vlan vlan-id | location { nas-ipip-address port port-number | portport-number } }*OptionalWhen binding the user to a remote port,you must use nas-ip ip-address to specifya remote access server IP address (here,ip-address is 127.0.0.1 by default,representing this device). When bindingthe user to a local port, you need not usenas-ip ip-address.z The following characters are not allowed in the user-name string: /:*?<>. And you cannot inputmore than one “@” in the string.z After the local-user password-display-mode cipher-force command is executed, any passwordwill be displayed in cipher mode even though you specify to display a user password in plain textby using the password command.z If a username and password is required for user authentication (RADIUS authentication as well aslocal authentication), the command level that a user can access after login is determined by theprivilege level of the user. For SSH users using RSA shared key for authentication, the commandsthey can access are determined by the levels set on their user interfaces.z If the configured authentication method is none or password authentication, the command levelthat a user can access after login is determined by the level of the user interface.z If the clients connected to a port have different authorized VLANs, only the first client passing theMAC address authentication can be assigned with an authorized VLAN. The switch will not assignauthorized VLANs for subsequent users passing MAC address authentication. In this case, youare recommended to connect only one MAC address authentication user or multiple users with thesame authorized VLAN to a port.z For local RADIUS authentication to take effect, the VLAN assignment mode must be set to stringafter you specify authorized VLANs for local users.Cutting Down User Connections ForciblyFollow these steps to cut down user connections forcibly:To do… Use the command… RemarksEnter system view system-view —