
26
Step
Command
Remarks
2.
Enable the default user
role feature.
role default-role enable
[
role-name
]
By default, the default user role
feature is disabled.
If you do not specify a user role, the
following default user role settings
apply:
•
For login to the default MDC, the
default user role is
network-operator.
•
For login to a non-default MDC,
the default user role is
mdc-operator.
If you do not use the
authorization-attribute user role
command to assign user roles to local
users, you must enable the default
user role feature.
Assigning user roles to remote AAA authentication users
For remote AAA authentication users, user roles are configured on the remote authentication server.
For information about configuring user roles for RADIUS users, see the RADIUS server
documentation. For HWTACACS users, the role configuration must use the
roles="role-1 role-2 …
role-n"
format, where user roles are space separated. For example, configure
roles="level-0
level-1 level-2"
to assign level-0, level-1, and level-2 to an HWTACACS user.
If the AAA server assigns the security-audit user role and other user roles to the same user, only the
security-audit user role takes effect.
Assigning user roles to local AAA authentication users
Configure user roles for local AAA authentication users in their local user accounts. Every local user
has a default user role. If this default user role is not suitable, remove it.
If a local user is the only user with the security-audit user role, the user cannot be deleted.
The security-audit user role is mutually exclusive with other user roles.
•
When you assign the security-audit user role to a local user, the system requests confirmation
to remove all the other user roles from the user.
•
When you assign the other user roles to a local user that has the security-audit user role, the
system requests confirmation to remove the security-audit role from the user.
To assign a user role to a local user:
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Create a local user and
enterits view.
local-user
user-name class
{
manage
|
network
}
N/A
Содержание FlexNetwork 10500 Series
Страница 139: ...130 Sysname display version ...