根据等保要求调整local-user权限,但配置错误,目前local-user均为用户查看权限,无管理权限。console所在local-user同样情况,导致通过console、vty登录均无设备的管理权限,应如何处理。是
根据等保要求调整local-user权限,但配置错误,目前local-user均为用户查看权限,无管理权限。console所在local-user同样情况,导致通过console、vty登录均无设备的管理权限,应如何处理。是
(0)
最佳答案
配置super权限了没,有的话可以提升一下权限。
更改权限后有没有保存设备,没有的话 可以重启一下。
都不行的话只能bootware里 更改了
(0)
未配置
local-user guest class manage service-type ssh terminal authorization-attribute user-role network-operator # local-user sec-audit class manage service-type ssh terminal authorization-attribute user-role security-audit # local-user system class manage service-type ssh terminal authorization-attribute user-role network-admin
local-user guest class manage service-type ssh terminal authorization-attribute user-role network-operator # local-user sec-audit class manage service-type ssh terminal authorization-attribute user-role security-audit # local-user system class manage service-type ssh terminal authorization-attribute user-role network-operator
下面这个是目前配置,都是network-operator
您好,像这种情况,是否只能通过恢复出厂设置进行解决?
通过bootware如何修改?
或者有其他权限高的用户进行修改,否则只能bootware修改了
bootware里下载配置文件,更改权限的配置,再上传到设备 就可以
https://zhiliao.h3c.com/Theme/details/3700
可参考如下配置:
配置账户角色
#
role name level-3
description Predefined level-3 role
rule 1 permit read write web-menu m_device/m_maintenance/m_changepassword
#
role name admin
description 系统管理
rule 1 permit read write execute feature
rule 2 permit read write execute web-menu
rule 3 deny read write execute web-menu m_monitor/
rule 4 deny read write execute web-menu m_resource/
rule 5 deny read write execute web-menu m_user/
rule 6 deny read write execute web-menu m_firewall/
rule 7 deny read write execute web-menu m_appsecurity/
rule 8 deny read write execute web-menu m_nat/
rule 9 deny read write execute web-menu m_vpn/
rule 10 deny read write execute web-menu m_loadbalance/
rule 11 deny read write execute web-menu m_network/
rule 12 deny read write execute web-menu m_secmonitor/
#
role name security-secret
description 安全保密管理
rule 1 permit read write execute feature
rule 2 permit read write execute web-menu
rule 3 deny read write execute web-menu m_dashboard/
rule 4 deny read write execute web-menu m_device/
rule 5 deny read write execute web-menu m_user/
rule 6 deny read write execute web-menu m_secmonitor/
#
配置三权账户
#
local-user admin class manage
service-type ftp
service-type telnet terminal https
authorization-attribute work-directory slot1#flash:
authorization-attribute user-role admin
password-control aging 7
password-control length 8
password-control composition type-number 3 type-length 1
password-control login-attempt 5 exceed lock-time 10
#
local-user audit class manage
service-type telnet terminal https
authorization-attribute user-role security-audit
password-control aging 7
password-control length 8
password-control composition type-number 3 type-length 1
password-control login-attempt 5 exceed lock-time 10
#
local-user secret class manage
service-type telnet terminal https
authorization-attribute work-directory slot1#flash:
authorization-attribute user-role level-3
authorization-attribute user-role security-secret
password-control aging 7
password-control length 8
password-control composition type-number 3 type-length 1
password-control login-attempt 5 exceed lock-time 10
#
使能HTTPS管理及WebUI日志功能
#
ip https enable
webui log enable
(0)
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
明白了,感谢!