Configuring User Role Switching; Configuration Guidelines - HP 12500 Configuration Manual

Routing switch series
Table of Contents

Advertisement

Step
3.
Specify a user role on the
user interface.

Configuring user role switching

You can switch to a different user role without reconnecting to the device. This operation does not change
the user role settings in the user account that you have been logged in with, and it is effective only for the
current login. The next time you are logged in with the user account, the original user role settings take
effect.

Configuration guidelines

A console user can switch the user role without authentication.
To enable AUX or VTY users to switch the user role, you must configure user role switching
authentication.
authentication modes and configuration requirements.
Local password authentication is available for switching to any user role, but remote AAA
authentication is available only for switching to a level-n user role.
If HWTACACS authentication is used, use a user account that has the target user role level or
a user role level higher than the target user role for role switching. For example, if the user
account test has the user role level-3, you can use this user account to switch the user role
among level-0, level-1, level-2, and level-3. In this approach, you must enter the correct
username and password to pass authentication.
If RADIUS authentication is used, you must create a user account for each level-n user role in the
$enabn$ format or the $enabn@domain-name$ format, where n represents the user role level.
In this approach, the username you enter is ignored. You can pass authentication as long as the
password is correct.
If you execute the quit command after switching to a user role, you are logged out of the current user
interface.
Command
user-role role-name
Table 7Authentication modes for user role switching
Remarks
Repeat this step to specify up to 64
user roles on a user interface.
By default:
23
Network-admin is specified on the
console user interface for
default-MDC login users, and
network-operator is specified on
any other user interface for
default-MDC login users.
After a default-MDC login user
uses the switchto mdc command to
log in to a non-default MDC, its
user role changes from
network-admin to mdc-admin.
The user role assigned to a
non-default MDC login user is
mdc-operator.
describes the available

Advertisement

Table of Contents
loading

Table of Contents