Denying Or Allowing Individual Commands; Template Accounts - Juniper J2300 User Manual

J-series services router
Hide thumbs Also See for J2300:
Table of Contents

Advertisement

Permission Bit
security-control
shell
snmp
snmp-control
system
system-control
trace
trace-control
view
Table 52: Predefined Login Classes
Login Class
operator
read-only
super-user and superuser
unauthorized

Denying or Allowing Individual Commands

By default, all top-level CLI commands have associated access privilege levels.
Users can execute only those commands and view only those statements for
which they have access privileges. For each login class, you can explicitly deny
or allow the use of operational and configuration mode commands that are
otherwise permitted or not allowed by a permission bit.

Template Accounts

You use local user template accounts when you need different types of templates.
Each template can define a different set of permissions appropriate for the group of
users who use that template. These templates are defined locally on the Services
Router and referenced by the TACACS+ and RADIUS authentication servers.
When you configure local user templates and a user logs in, the JUNOS software
issues a request to the authentication server to authenticate the user's login
name. If a user is authenticated, the server returns the local username to
the router, which then determines whether a local username is specified for
that login name (
Access
Can view and configure security information (at the [edit security] hierarchy level).
Can start a local shell on the router by entering the start shell command.
Can view SNMP configuration information in configuration and operational modes.
Can view SNMP configuration information and configure SNMP (at the [edit snmp]
hierarchy level).
Can view system-level information in configuration and operational modes.
Can view system-level configuration information and configure it (at the [edit system]
hierarchy level).
Can view trace file settings in configuration and operational modes.
Can view trace file settings and configure trace file properties.
Can use various commands to display current systemwide, routing table, and
protocol-specific values and statistics.
Permission Bits Set
clear, network, reset, trace, view
view
all
None
for TACACS+,
local-username
Managing Users and Operations
for RADIUS). If
Juniper-Local-User
System Management Overview
167

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

J2350J2320J4300J6300J6350J4350

Table of Contents