EM316LNXNM-OT
Authentication, Authorization, and
Accounting
PN 1275005-100 Rev E6
82
Set the minimum privilege level corresponding to the VIEW access class (default=1):
fiberdriver(config)# aaa remote-server <1-5> priv-view <0-13>
The following commands restore the named parameter to its default value for the given remote server (1-5):
fiberdriver(config)# default aaa remote-server <1-5> port
fiberdriver(config)# default aaa remote-server <1-5> timeout
fiberdriver(config)# default aaa remote-server <1-5> retries
fiberdriver(config)# default aaa remote-server <1-5> server
fiberdriver(config)# default aaa remote-server <1-5> protocol
fiberdriver(config)# default aaa remote-server <1-5> priv-super
fiberdriver(config)# default aaa remote-server <1-5> priv-normal
fiberdriver(config)# default aaa remote-server <1-5> priv-view
The following command restores all parameters to their default values for the given remote server (1-5):
fiberdriver(config)# default aaa remote-server <1-5>
To delete a remote server, use the
no aaa remote-server host X
command where X is the desired
host you wish to remove. For example, delete the remote server host above with the following command:
fiberdriver(config)# no aaa remote-server host 1
10.1.4. Configuring Authentication
By default, authentication is disabled. To turn on authentication, use the command
aaa
authentication
. To turn off authentication, use the command
no aaa authentication
.
10.1.5. Configuring Accounting
By default, accounting is disabled. To turn on accounting, use the command
aaa accounting
. To turn
off accounting, use the command
no aaa accounting
.
10.1.6. Configuring General Remote User Access
As stated in the Authorization section, a remotely authenticated user that is not recognized locally is treated
as the special user "$remote$". This special user is used only to assign group permissions for all users in
groups without a local user. The user "$remote$" is included in each new Fiber Driver system. This user
is added to group "all", which has access to the entire chassis. The user may not be added in upgrades
from a previous version.
Use the command
show users
to see the permissions of each user. Use the standard user commands
from the "Users, Classes, and Logging In and Out" section to setup the group permission.
fiberdriver(config)# show users
username $remote$ groups all
username admin password encrypted $1$kQ2rIq/$Ob8wFa2EW135XC4TnN7wJ/ class debug
username admin groups all