Examples Using Privilege Group Membership - Juniper SYSTEM BASICS - CONFIGURATION GUIDE V 11.1.X Configuration Manual

System basics configuration guide software for e series broadband services routers
Table of Contents

Advertisement

Privilege group 0 is not a member of any group and you cannot assign member
groups to it, but it is reachable from every privilege group.
Numbers in the range 0 15 identify the 16 privilege groups. Each of the 16 groups
can have a name or an alias. The default internal name is the privilege group number.
By default, the groups are hierarchical and each group, with the exception of groups
1 and 0, contains one group. When a group contains a group, the contained group
is a member of the original group: privilege group p has one member, privilege group
p-1. For example, privilege group 15 has member 14, privilege group 14 has member
13, and privilege group 2 has member 1.
For hierarchical groups, groups 0 through 14 are reachable from privilege group 15,
groups 0 through 13 are reachable from privilege group 14, groups 0 to 4 are
reachable from 5, and so forth. Hierarchical groups can also contain other privilege
groups. For example, group A is reachable from group B if group A is a member of
group B or is a member of a group that is a member of group B. If group X has
member Y and Y has member Z then Z is reachable from X.
You cannot configure circular dependencies. For example, you cannot configure a
circular dependency where group X has member Y, Y has member Z, Z has member
P, and X can reach Z and P. Group X cannot have member Z or P because Z and P
are reachable through Y.

Examples Using Privilege Group Membership

In each of the following examples, privilege groups are at the default setting, where
privilege group 0 is reachable from every privilege group, 15 contains 14, 14 contains
13, 13 contains 12, and so forth. The commands in each example change the privilege
group settings from the default.
Example 1
In Example 1:
Example 2
In Example 2:
host1(config)#privilege-group membership clear 11
host1(config)#privilege-group membership 15 add 10
Privilege group 11 does not contain any privilege groups
Privilege group 15 contains group 10. Therefore, privilege group 10 and all groups
contained or reachable from privilege group 10 are now reachable from privilege
group 15.
Because privilege group 15 already contains privilege group 14, all groups with
the exception of privilege group 11 are reachable from privilege group 15.
A command that is in privilege group 11 can only be executed by a user at
privilege 11. A user at any other privilege does not have access to privilege group
11 commands.
host1(config)#privilege-group membership 14 remove 13
Privilege group 14 does not contain any privilege groups.
Chapter 2: Command-Line Interface
CLI Command Privileges
53

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the SYSTEM BASICS - CONFIGURATION GUIDE V 11.1.X and is the answer not in the manual?

Questions and answers

This manual is also suitable for:

Junose 11.1

Table of Contents