Assigning User Roles - HP FlexFabric 7900 Series Configuration Manual

Hide thumbs Also See for FlexFabric 7900 Series:
Table of Contents

Advertisement

User role name
level-n (n = 0 to 15)

Assigning user roles

You assign access rights to users by assigning at least one user role. The users can use the collection of
commands and resources accessible to any user role assigned to them. For example, you can access any
interface to use the qos apply policy command if you are assigned the following user roles:
User role A denies access to the qos apply policy command and permits access to only interface
FortyGigE 1/0/1.
User role B permits access to the qos apply policy command and all interfaces.
Depending on the authentication method, user role assignment has the following methods:
AAA authorization—If scheme authentication is used, the AAA module handles user role
assignment.
If the user passes local authorization, the device assigns the user roles specified in the local user
account.
If the user passes remote authorization, the remote AAA server assigns the user roles specified
on the server. The AAA server can be a RADIUS or HWTACACS server.
None-AAA authorization—If the user uses password authentication or no authentication, the device
assigns user roles specified on the user line. This method also applies to SSH clients that use
publickey or password-publickey authentication. User roles assigned to these SSH clients are
specified in their respective device management user accounts.
For more information about AAA and SSH, see Security Configuration Guide. For more information
about user line, see
Permissions
level-0—Has access to diagnostic commands, including ping, quit,
ssh2, super, system-view, telnet, and tracert. Level-0 access rights are
configurable.
level-1—Has access to the display commands (except display
history-command all) of all features and resources in the system, in
addition to all access rights of the user role level-0. Level- 1 access rights
are configurable.
level-2 to level-8, and level-10 to level-14—Have no access rights by
default. Access rights are configurable.
level-9—Has access to all features and resources except those in the
following list. If you are logged in with a local user account that has a
level-9 user role, you can change the password in the local user account.
Level-9 access rights are configurable.
RBAC non-debugging commands.
Local users.
File management.
Device management.
The display history-command all command.
level-15—Has the same rights as network-admin.
"Login
overview" and
"Logging in to the
CLI."
46

Advertisement

Table of Contents
loading

Table of Contents