请问系统有预定义的用户角色名和对应的权限,通过authorization-attribute user-role network-admin,给用户一个admin权限
那自己定义一个用户比如 authorization-attribute user-role XXX,那这个XXX有哪些权限?
(0)
最佳答案
[sw]-luser-manage-admin]authorization-attribute user-role ?
STRING<1-63> User role name
network-admin
network-operator
context-admin
context-operator
level-0
level-1
level-2
level-3
level-4
level-5
level-6
level-7
level-8
level-9
level-10
level-11
level-12
level-13
level-14
level-15
security-audit
guest-manager
system-admin
security-admin
audit-admin
(0)
请问audit-admin 这个有哪些权限,好像有一些交换机没这个权限
审计的权限,查、读的权限类ping啊、tracert、dis ip之类的
el-n (n = 0~15) | · level-0:可执行命令ping、tracert、ssh2、telnet和super,且管理员可以为其配置权限 · level-1:具有level-0用户角色的权限,并且可执行系统所有功能和资源的相关display命令(除display history-command all之外),以及管理员可以为其配置权限 · level-2~level-8和level-10~level-14:无缺省权限,需要管理员为其配置权限 · level-9:可操作系统中绝大多数的功能和所有的资源,且管理员可以为其配置权限,但不能操作display history-command all命令、RBAC的命令(Debug命令除外)、MDC、文件管理、设备管理以及本地用户特性。对于本地用户,若用户登录系统并被授予该角色,可以修改自己的密码 · level-15:在缺省MDC中,具有与network-admin角色相同的权限;在非缺省MDC中,具有与mdc-admin角色相同的权限 |
(0)
帐号配置权限可参考如下配置:
#
role name level-3
description Predefined level-3 role
rule 1 permit read write web-menu m_device/m_maintenance/m_changepassword
#
role name admin
description 系统管理
rule 1 permit read write execute feature
rule 2 permit read write execute web-menu
rule 3 deny read write execute web-menu m_monitor/
rule 4 deny read write execute web-menu m_resource/
rule 5 deny read write execute web-menu m_user/
rule 6 deny read write execute web-menu m_firewall/
rule 7 deny read write execute web-menu m_appsecurity/
rule 8 deny read write execute web-menu m_nat/
rule 9 deny read write execute web-menu m_vpn/
rule 10 deny read write execute web-menu m_loadbalance/
rule 11 deny read write execute web-menu m_network/
rule 12 deny read write execute web-menu m_secmonitor/
#
role name security-secret
description 安全保密管理
rule 1 permit read write execute feature
rule 2 permit read write execute web-menu
rule 3 deny read write execute web-menu m_dashboard/
rule 4 deny read write execute web-menu m_device/
rule 5 deny read write execute web-menu m_user/
rule 6 deny read write execute web-menu m_secmonitor/
#
配置三权账户
#
local-user admin class manage
service-type ftp
service-type telnet terminal https
authorization-attribute work-directory slot1#flash:
authorization-attribute user-role admin
password-control aging 7
password-control length 8
password-control composition type-number 3 type-length 1
password-control login-attempt 5 exceed lock-time 10
#
local-user audit class manage
service-type telnet terminal https
authorization-attribute user-role security-audit
password-control aging 7
password-control length 8
password-control composition type-number 3 type-length 1
password-control login-attempt 5 exceed lock-time 10
#
local-user secret class manage
service-type telnet terminal https
authorization-attribute work-directory slot1#flash:
authorization-attribute user-role level-3
authorization-attribute user-role security-secret
password-control aging 7
password-control length 8
password-control composition type-number 3 type-length 1
password-control login-attempt 5 exceed lock-time 10
#
使能HTTPS管理及WebUI日志功能
#
ip https enable
webui log enable
(0)
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
审计的权限,查、读的权限类ping啊、tracert、dis ip之类的