1-11
Level
Privilege
Description
3 Manage
Influences the basic operation of the system and the
system support modules for service support. By default,
commands at this level involve file system, FTP, TFTP,
Xmodem command download, user management, level
setting, as well as parameter setting within a system (the
last case involves those non-protocol or non RFC
provisioned commands).
Configuring user privilege level
User privilege level can be configured by using AAA authentication parameters or under a user
interface.
1) Configure user privilege level by using AAA authentication parameters
If the user interface authentication mode is
scheme
when a user logs in, and username and password
are needed at login, then the user privilege level is specified in the configuration of AAA authentication.
Follow these steps to configure user privilege level by using AAA authentication parameters:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Enter user interface view
user-interface
{
first-num1
[
last-num1
] | {
aux
|
vty
}
first-num2
[
last-num2
] }
—
Configure the authentication
mode for logging in to the user
interface as
scheme
authentication-mode
scheme
Required
By default, the authentication
mode for VTY users is
password
, and no
authentication is needed for
AUX users.
Exit to system view
quit
—
Configure the authentication
mode for SSH users as
password
For the details, refer to
SSH2.0
Configuration
in the
Security
Volume.
Required if users use SSH to
log in, and username and
password are needed at
authentication
Using local
authentication
z
Use the
local-user
command to create a local
user and enter local user
view.
z
Use the
level
keyword in the
authorization-attribute
command to configure the
user level.
Configure the
user privilege
level by using
AAA
authentication
parameters
Using remote
authentication
(RADIUS,
HWTACACS,
and LDAP
authentication
s)
Configure user level on the
authentication server
User either approach
z
For local authentication, if
you do not configure the
user level, the user level is
0, that is, users of this level
can use commands with
level 0 only.
z
For remote authentication, if
you do not configure the
user level, the user level
depends on the default
configuration of the
authentication server.
Содержание S7902E
Страница 82: ...1 4 DeviceA interface tunnel 1 DeviceA Tunnel1 service loopback group 1 ...
Страница 200: ...1 11 DeviceB display vlan dynamic No dynamic vlans exist ...
Страница 494: ...ii Displaying and Maintaining Tunneling Configuration 1 45 Troubleshooting Tunneling Configuration 1 45 ...
Страница 598: ...ii ...
Страница 1757: ...4 9 ...
Страница 1770: ...6 4 ...
Страница 2017: ...2 11 Figure 2 3 SFTP client interface ...
Страница 2062: ...i Table of Contents 1 URPF Configuration 1 1 URPF Overview 1 1 What is URPF 1 1 How URPF Works 1 1 Configuring URPF 1 2 ...
Страница 2238: ...1 16 DeviceA cfd linktrace service instance 1 mep 1001 target mep 4002 ...
Страница 2442: ...2 4 Set the interval for sending Syslog or trap messages to 20 seconds Device mac address information interval 20 ...