Cisco APIC Security Configuration Guide, Release 6.2(x)

PDF

Cisco APIC Security Configuration Guide, Release 6.2(x)

Configure user lockout after continuous failed attempts to log in using the GUI

Want to summarize with AI?

Log in

Configure user lockout settings to block users from logging in after a specified number of failed login attempts within a defined time period.


Configure user lockout settings to enhance security by preventing brute force attacks and unauthorized access attempts.

You can block a user from being able to log in after the user fails a configured number of login attempts. You can specify how many failed login attempts the user can have within a specific time period. If the user fails to log in too many times, then that user becomes unable to log in for a specified period of time.

Procedure

  1. On the menu bar, choose Admin > AAA.

  2. In the Navigation pane, choose Security.

  3. In the Work pane, check you are in the Security Default Settings tab.

  4. Click the pencil icon, to modify the following fields:

    1. For Lockout User after multiple failed login attempts, choose Enable.
    2. For Number of failed attempts before user is locked out, enter the desired value.

      The range is from 1 to 15. The default is 5.

    3. For Time period in which consecutive attempts were failed (m), enter a value in minutes for the time interval during which the Cisco Application Policy Infrastructure Controller (APIC) will count the failed attempts.

      The range is from 1 to 720. The default is 5.

    4. For Duration of lockout (m), enter a value in minutes for how long a user will be locked out for failing to log in too many times.
  5. Click Submit.

The user lockout configuration is saved and will be enforced for future login attempts.