1-11
To do…
Use the command…
Remarks
Using local
authentication
z
Use the
local-user
command to create a local
user and enter local user
view.
z
Use the
level
keyword in the
authorization-attribute
command to configure the
user level.
Configure the
user privilege
level by using
AAA
authentication
parameters
Using remote
authentication
(RADIUS,
HWTACACS,
and LDAP
authentication
s)
Configure user level on the
authentication server
User either approach
z
For local authentication, if
you do not configure the
user level, the user level is
0, that is, users of this level
can use commands with
level 0 only.
z
For remote authentication, if
you do not configure the
user level, the user level
depends on the default
configuration of the
authentication server.
z
For the description of user interface, refer to
User Interface Configuration
in the
System Volume
;
for the description of the
user-interface
,
authentication-mode
and
user privilege level
commands, refer to
Login Commands
in the
System Volume
.
z
For the introduction to AAA authentication, refer to
AAA Configuration
in the
Security Volume
; for
the description of the
local-user
and
authorization-attribute
commands, refer to
AAA Commands
in the
Security Volume
.
z
For the introduction to SSH, refer to
SSH 2.0 Configuration
in the
Security Volume
.
2) Example of configuring user privilege level by using AAA authentication parameters
# Authenticate the users telnetting to the device through VTY 1, verify their usernames and passwords
locally, and specify the user privilege level as 3.
<Sysname> system-view
[Sysname] user-interface vty 1
[Sysname-ui-vty1] authentication-mode scheme
[Sysname-ui-vty1] quit
[Sysname] local-user test
[Sysname-luser-test] password cipher 123
[Sysname-luser-test] service-type telnet
After the above configuration, when users telnet to the device through VTY 1, they need to input
username
test
and password
123
. After passing the authentication, users can only use the commands
of level 0. If the users need to use commands of levels 0, 1, 2 and 3, the following configuration is
required:
[Sysname-luser-test] authorization-attribute level 3
3) Configure the user privilege level under a user interface
If the user interface authentication mode is
scheme
when a user logs in, and SSH
publickey
authentication type (only username is needed for this authentication type) is adopted, then the user
privilege level is the user interface level; if a user logs in using the
none
or
password
mode (namely, no
username is needed), the user privilege level is the user interface level.
Содержание S5810 Series
Страница 307: ...ii Configured Multicast Group Policy Fails to Take Effect 1 32...
Страница 648: ...1 8 Return to the upper directory Sysname cd Display the current working directory Sysname pwd flash...
Страница 812: ...1 7 Role Slave Sysname stack_3 DeviceD Device type S5810 50S MAC address 000f e200 1003...