Can I change the number of failed MMP user login attempts before a 15 minute lockout occurs?


Yes. Use the MPP command "user rule max_failed_logins <attempts>"  and set the number of failed login attempts allowed for an MMP user, before the user is locked out of the MMP for 15 minutes. The Call Bridge needs to be restarted for user rule max_failed_logins <attempts> to take effect. Changes are immediately applied to MMP users.

Note: The 15 minute lockout also applies to Cisco Meeting App users that authenticate via LDAP but exceed the specified number of failed login attempts. Guest access to meetings held on the Meeting Server are unaffected.

A locked MMP users can be unlocked by an MMP admin, but it is not possible to unlock an Cisco Meeting App user who is authenticated through LDAP before the lockout timer expires.

If no maximum number of failed logins is configured, then the lockout mechanism is disabled for MMP users, but it defaults to 20 failed attempts for Cisco Meeting App users authenticated through LDAP.

It is not possible to change the lockout duration.

Last update:
07-Jan-2020
FAQ ID:
1473