H3C S5120-SI Series Operation Manual page 607

Hide thumbs Also See for S5120-SI Series:
Table of Contents

Advertisement

To do...
Using local
authentication
Configure the
user privilege
level by using
AAA
authentication
Using remote
parameters
authentication
(RADIUS and
LDAP
authentication
s)
For the description of user interface, refer to User Login Configuration; for the description of the
user-interface, authentication-mode and user privilege level commands, refer to Login
Commands.
For the introduction to AAA authentication, refer to AAA Configuration; for the description of the
local-user and authorization-attribute commands, refer to AAA Commands.
For the introduction to SSH, refer to SSH 2.0 Configuration.
2)
Example of configuring user privilege level by using AAA authentication parameters
# Authenticate the users telnetting to the device through VTY 1, verify their usernames and passwords
locally, and specify the user privilege level as 3.
<Sysname> system-view
[Sysname] user-interface vty 1
[Sysname-ui-vty1] authentication-mode scheme
[Sysname-ui-vty1] quit
[Sysname] local-user test
[Sysname-luser-test] password cipher 123
[Sysname-luser-test] service-type telnet
After the above configuration, when users telnet to the device through VTY 1, they need to input
username test and password 123. After passing the authentication, users can only use the commands
of level 0. If the users need to use commands of levels 0, 1, 2 and 3, the following configuration is
required:
[Sysname-luser-test] authorization-attribute level 3
3)
Configure the user privilege level under a user interface
If the user interface authentication mode is scheme when a user logs in, and SSH publickey
authentication type (only username is needed for this authentication type) is adopted, then the user
privilege level is the user interface level; if a user logs in using the none or password mode (namely, no
username is needed), the user privilege level is the user interface level.
Use the command...
Use
the
local-user
command to create a local
user and enter local user
view.
Use the level keyword in the
authorization-attribute
command to configure the
user level.
Configure user level on the
authentication server
1-11
Remarks
User either approach
For local authentication, if
you do not configure the
user level, the user level is
0, that is, users of this level
can use commands with
level 0 only.
For remote authentication, if
you do not configure the
user level, the user level
depends on the default
configuration
of
authentication server.
the

Advertisement

Table of Contents
loading

Table of Contents