各位大神是否使用过***.***作为comware v7设备的aaa服务器,在***.***的authorization.xml文件中应该如何下发login用户的角色权限。我在配置文档里看到“HWTACACS 服务器上的授权角色配置必须满足格式:roles="name1 name2 namen",具体在authorization.xml文件中应该如何写呢??本人的配置如下:
- <Authorization> - <!-- This entry will only be processed in the times given below --> - <!-- <Time>MTWRFSN,04:00-21:00</Time> --> - <!-- This authorization section applies to the following user groups. In case of conflicting authorization entries for the same group, the entry which appears first in the file is used. --> - <UserGroups> <UserGroup>Network Engineering</UserGroup> </UserGroups> - <!-- This authorization section applies to the following client groups. In case of conflicting authorization entries for the same client group, the entry which appears first in the file is used. --> - <!-- If no client groups are specified then the settings are applied to the specified usergroups irrespective of the clients they come from --> - <ClientGroups> <ClientGroup>H3C-Comware7</ClientGroup> </ClientGroups> - <AutoExec> <Set>shell:roles=network-admin</Set> </AutoExec> - <Shell> - <!-- note that the login and exit commands are always permitted --> <Permit>.*</Permit> - <!-- This will allow all show commands --> <Deny>.*</Deny> - <!-- This will deny all other commands --> </Shell> </Authorization>
(0)
最佳答案
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
暂无评论