Privilege group 0 is not a member of any group and you cannot assign member
groups to it, but it is reachable from every privilege group.
Numbers in the range 0—15 identify the 16 privilege groups. Each of the 16 groups
can have a name or an alias. The default internal name is the privilege group number.
By default, the groups are hierarchical and each group, with the exception of groups
1 and 0, contains one group. When a group contains a group, the contained group
is a member of the original group: privilege group p has one member, privilege group
p-1. For example, privilege group 15 has member 14, privilege group 14 has member
13, and privilege group 2 has member 1.
For hierarchical groups, groups 0 through 14 are reachable from privilege group 15,
groups 0 through 13 are reachable from privilege group 14, groups 0 to 4 are
reachable from 5, and so forth. Hierarchical groups can also contain other privilege
groups. For example, group A is reachable from group B if group A is a member of
group B or is a member of a group that is a member of group B. If group X has
member Y and Y has member Z then Z is reachable from X.
You cannot configure circular dependencies. For example, you cannot configure a
circular dependency where group X has member Y, Y has member Z, Z has member
P, and X can reach Z and P. Group X cannot have member Z or P because Z and P
are reachable through Y.
Examples Using Privilege Group Membership
In each of the following examples, privilege groups are at the default setting, where
privilege group 0 is reachable from every privilege group, 15 contains 14, 14 contains
13, 13 contains 12, and so forth. The commands in each example change the privilege
group settings from the default.
Example 1
host1(config)#
privilege-group membership clear 11
host1(config)#
privilege-group membership 15 add 10
In Example 1:
■
Privilege group 11 does not contain any privilege groups
■
Privilege group 15 contains group 10. Therefore, privilege group 10 and all groups
contained or reachable from privilege group 10 are now reachable from privilege
group 15.
■
Because privilege group 15 already contains privilege group 14, all groups with
the exception of privilege group 11 are reachable from privilege group 15.
■
A command that is in privilege group 11 can only be executed by a user at
privilege 11. A user at any other privilege does not have access to privilege group
11 commands.
Example 2
host1(config)#
privilege-group membership 14 remove 13
In Example 2:
■
Privilege group 14 does not contain any privilege groups.
CLI Command Privileges
■
53
Chapter 2: Command-Line Interface
Содержание JUNOSe 11.1
Страница 6: ...vi...
Страница 8: ...viii JUNOSe 11 1 x System Basics Configuration Guide...
Страница 24: ...xxiv List of Figures JUNOSe 11 1 x System Basics Configuration Guide...
Страница 32: ...2 Chapters JUNOSe 11 1 x System Basics Configuration Guide...
Страница 58: ...28 Configuring Remote Access JUNOSe 11 1 x System Basics Configuration Guide...
Страница 176: ...146 Downgrading JUNOSe Software JUNOSe 11 1 x System Basics Configuration Guide...
Страница 280: ...250 Monitoring SNMP JUNOSe 11 1 x System Basics Configuration Guide...
Страница 384: ...354 Monitoring the System JUNOSe 11 1 x System Basics Configuration Guide...
Страница 446: ...416 Monitoring Modules JUNOSe 11 1 x System Basics Configuration Guide...
Страница 580: ...550 Monitoring Virtual Routers JUNOSe 11 1 x System Basics Configuration Guide...
Страница 581: ...Part 2 Reference Material Abbreviations and Acronyms on page 553 References on page 571 Reference Material 551...
Страница 582: ...552 Reference Material JUNOSe 11 1 x System Basics Configuration Guide...
Страница 622: ...592 Hardware Standards JUNOSe 11 1 x System Basics Configuration Guide...
Страница 623: ...Part 3 Index Index on page 595 Index 593...
Страница 624: ...594 Index JUNOSe 11 1 x System Basics Configuration Guide...
Страница 640: ...610 Index JUNOSe 11 1 x System Basics Configuration Guide...