1-15
A user can switch to a privilege level equal to or lower than the current one unconditionally and is not
required to input the password (if any). A user is required to input the password (if any) to switch to a
higher privilege level for security sake.
The authentication falls into one of the following four categories:
local
,
scheme
,
local
scheme
, and
scheme
local
. You can specify the authentication mode as required.
When a user switches to a privilege level higher than the current one, the switch procedure varies with
authentication modes:
z
local
: In this mode, after the user executes the command to switch the user privilege level, the
system asks the user to input the local switch authentication password set with the
super
password
command. If the user passes the authentication, the user privilege level will be
switched successfully; otherwise, the user privilege level will remain unchanged.
z
scheme
: In this mode, after the user executes the command to switch the user privilege level, the
system asks the user to input this user’s switch password configured on the AAA server. If the
user passes the AAA authentication, the user privilege level will be switched successfully;
otherwise, the user privilege level will remain unchanged.
z
local scheme
: In this mode, after the user executes the command to switch the user privilege
level, the system asks the user to input the local switch authentication password. With the local
switch authentication password configured, if the user passes the authentication, the user
privilege level will be switched successfully; otherwise, the user privilege level will remain
unchanged. With no local switch authentication password configured, the AAA authentication is
performed: if the user passes the AAA authentication, the user privilege level will be switched
successfully; otherwise, the user privilege level will remain unchanged.
z
scheme local
: In this mode, after the user executes the command to switch the user privilege
level, the system asks the user to input this user’s switch password configured on the AAA server.
If the user passes the AAA authentication, the user privilege level will be switched successfully;
otherwise, the user privilege level will remain unchanged. If the AAA configuration is invalid or the
AAA server does not respond, the authentication requiring the local password is performed: if the
user passes the authentication, the user privilege level will be switched successfully; otherwise,
the user privilege level will remain unchanged.
If the authentication mode is set to
scheme
(performs authorization and authentication of AAA) when
the user logs in to the switch (that is, username and password are required when the user logs in), the
AAA authentication is performed when the user switches his privilege level: the system asks the user to
input the privilege level switch password; after the user inputs the password, the device uses the
username used to log in to the switch and the privilege level switch password to perform the privilege
level switch authentication.
Follow these steps to configure user privilege level switch:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Содержание S7902E
Страница 82: ...1 4 DeviceA interface tunnel 1 DeviceA Tunnel1 service loopback group 1 ...
Страница 200: ...1 11 DeviceB display vlan dynamic No dynamic vlans exist ...
Страница 494: ...ii Displaying and Maintaining Tunneling Configuration 1 45 Troubleshooting Tunneling Configuration 1 45 ...
Страница 598: ...ii ...
Страница 1757: ...4 9 ...
Страница 1770: ...6 4 ...
Страница 2017: ...2 11 Figure 2 3 SFTP client interface ...
Страница 2062: ...i Table of Contents 1 URPF Configuration 1 1 URPF Overview 1 1 What is URPF 1 1 How URPF Works 1 1 Configuring URPF 1 2 ...
Страница 2238: ...1 16 DeviceA cfd linktrace service instance 1 mep 1001 target mep 4002 ...
Страница 2442: ...2 4 Set the interval for sending Syslog or trap messages to 20 seconds Device mac address information interval 20 ...