6-77
RADIUS Authentication, Authorization, and Accounting
Creating Local Privilege Levels
N o t e
Commands are expanded before the comparison is done, for example,
sh ver
would be expanded to
show version
and then this command is compared
against the command strings of the authorization group.
Figure 6-34. Example of Creating a Local Authorization Group and Assigning the Commands that are
Authorized for the Group
When a command must be preceded by the execution of another command,
then both commands need to be permitted for the command authorization
group. For example, you must execute the
configure
command before you can
enter the
vlan
context, so both commands must be permitted.
Figure 6-35. Example of Configuring Authorized Commands for a Group in the Correct Order
Some commands cause the switch CLI to enter a special context, such as test
mode, and the input is not processed by the normal CLI. Keyboard input is not
checked against the command authorization group. If these special contexts
are permitted, the user can proceed outside the control and logging of the
command group configuration.
Configuring a Local User for a Group
Local manager user logins and authorized command configuration are mutu-
ally exclusive with RADIUS or TACACS authentication and with RADIUS
authorization and accounting.
HP Switch(config)# aaa authorization group Bluegroup 100 match-command configure
permit
HP Switch(config)# aaa authorization group Bluegroup 200 match-command telnet
permit
HP Switch(config)# aaa authorization group Bluegroup 300 match-command menu
permit
HP Switch(config)# aaa authorization group Redgroup 100 match-command configure
permit
HP Switch(config)# aaa authorization group Redgroup 200 match-command “vlan *”
permit
Содержание HP ProCurve Series 6600
Страница 2: ......
Страница 6: ...iv ...
Страница 26: ...xxiv ...
Страница 102: ...2 48 Configuring Username and Password Security Password Recovery ...
Страница 204: ...4 72 Web and MAC Authentication Client Status ...
Страница 550: ...10 130 IPv4 Access Control Lists ACLs General ACL Operating Notes ...
Страница 612: ...12 24 Traffic Security Filters and Monitors Configuring Traffic Security Filters ...
Страница 734: ...14 44 Configuring and Monitoring Port Security Operating Notes for Port Security ...
Страница 756: ...16 8 Key Management System Configuring Key Chain Management ...
Страница 776: ...20 Index web server proxy 14 42 webagent access 6 6 wildcard See ACL wildcard See ACL ...
Страница 777: ......