Chapter 9 Managing Users And Operations; Login Classes; Permission Bits - Juniper J2300 User Manual

J-series services router
Hide thumbs Also See for J2300:
Table of Contents

Advertisement

Login Classes

All users who log into the Services Router must be in a login class. With
login classes, you define the following:
You can define any number of login classes. You then apply one login class to an
individual user account. The software contains a few predefined login classes,
which are listed in Table 52. The predefined login classes cannot be modified.

Permission Bits

Each top-level command-line interface (CLI) command and each configuration
statement has an access privilege level associated with it. Users can execute
only those commands and configure and view only those statements for which
they have access privileges. The access privileges for each login class are
defined by one or more permission bits (see Table 51).
Two forms for the permissions control the individual parts of the configuration:
must be unique within the router. If you do not assign a UID to a username,
the software assigns one when you commit the configuration, preferring the
lowest available number.
User's access privilege—You can create login classes with specific permission
bits or use one of the default classes listed in Table 52.
Authentication method or methods and passwords that the user can use to
access the router—You can use SSH or an MD5 password, or you can enter
a plain-text password that the JUNOS software encrypts using MD5-style
encryption before entering it in the password database. If you configure
the plain-text-password option, you are prompted to enter and confirm the
password.
Access privileges users have when they are logged into the router. For more
information, see "Permission Bits" on page 165.
Commands and statements that users can and cannot specify. For more
information, see "Denying or Allowing Individual Commands" on page 167.
How long a login session can be idle before it times out and the user is
logged off.
"Plain" form—Provides read-only capability for that permission type. An
example is
.
interface
Form that ends in
-control
permission type. An example is
—Provides read and write capability for that
.
interface-control
System Management Overview
Managing Users and Operations
165

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

J2350J2320J4300J6300J6350J4350

Table of Contents