28
Step
Command
Remarks
3.
Specify a user role on the
user line.
user-role role-name
Repeat this step to specify a
maximum of 64 user roles on a user
line.
The following MDC default settings
apply:
•
The network-admin user role is
specified on the AUX user line
for default-MDC login users. The
network-operator user role is
specified on any other user line
for default-MDC login users.
•
The network-admin user role of
default-MDC login users
changes to mdc-admin after the
users use the
switchto mdc
command to log into non-default
MDCs.
•
The mdc-operator user role is
specified on user lines for other
non-default MDC login users.
The device cannot assign the
security-audit user role to non-AAA
authentication users.
Configuring temporary user role authorization
Temporary user role authorization allows you to obtain another user role without reconnecting to the
device. This feature is useful when you want to use a user role temporarily to configure a feature.
Temporary user role authorization is effective only on the current login. This feature does not change
the user role settings in the user account that you have been logged in with. The next time you are
logged in with the user account, the original user role settings take effect.
Configuration restrictions and guidelines
When you configure temporary user role authorization, follow these restrictions and guidelines:
•
To enable a user to obtain another user role without reconnecting to the device, you must
configure user role authentication.
describes the available authentication modes and
configuration requirements.
•
If HWTACACS authentication is used, the following rules apply:
The device uses the entered username and password to request role authentication, and it
sends the username to the server in the
username
or
username
@
domain-name
format.
Whether the domain name is included in the username depends on the
user-name-format
command in the HWTACACS scheme.
To obtain a level-
n
user role, the user account on the server must have the target user role
level or a level higher than the target user role. A user account that obtains the level-
n
user
role can obtain any user role among level 0 through level-
n
.
To obtain a non-level-
n
user role, make sure the user account on the server meets the
following requirements:
−
The account has a user privilege level.
−
The HWTACACS custom attribute is configured for the account in the form of
allowed-roles="role"
. The variable
role
represents the target user role.
Содержание FlexNetwork 10500 Series
Страница 139: ...130 Sysname display version ...