Skip to main content
Version: 7.25

user


user​

Type: Directory

Router administration user accounts. Each user belongs to exactly one group that grants the rights (policies) the user has. See User for the full guide.

FlagNameDescription
EexpiredPassword expired with /user/expire-password. At the next interactive login the user is asked to set a new password; setting a new password clears the flag.
XdisabledUser account is disabled and cannot log in.
ArgumentTypeDescription
name ( mandatory )stringLogin user name. Letters, digits and the characters _ . # - @ are allowed; the name must end with a letter or a digit and cannot start with . or -.
group ( mandatory )enumUser group that grants the rights (policies) the user has.
password ( mandatory )stringLogin password. Any characters are accepted, including spaces, symbols and UTF-8. An explicitly empty value (password="") allows logging in with a blank password. The complexity policy from /user/settings applies when set.
inactivity-timeouttimeIdle time after which inactivity-policy is applied to an interactive console session. Range 00:01:00 to 1d00:00:00. Default: 10m.
inactivity-policyenum (none | logout | lockscreen)

Action taken when inactivity-timeout expires:

  • none (default) - The idle session keeps running.
  • logout - Closes the idle session with the message "<name> was logged out due to inactivity".
  • lockscreen - Locks the session ("Session is locked (Ctrl-D to Quit)") and asks for the user's password to resume; wrong passwords print "Sorry, try again.".
addressobject { address: alt { address: ipPrefix , address: ip6Prefix } }IP address with mask or IPv6 prefix. When set, the user may log in only from matching source addresses; logins from other addresses are refused.
Read-only ArgumentTypeDescription
last-logged-indateDate and time of the user's last login.