02.10.2013 Views

FTOS Configuration Guide for the C-Series - Force10 Networks

FTOS Configuration Guide for the C-Series - Force10 Networks

FTOS Configuration Guide for the C-Series - Force10 Networks

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Configuring custom privilege levels<br />

In addition to assigning privilege levels to <strong>the</strong> user, you can configure <strong>the</strong> privilege levels of commands so<br />

that <strong>the</strong>y are visible in different privilege levels. Within <strong>FTOS</strong>, commands have certain privilege levels.<br />

With <strong>the</strong> privilege command, <strong>the</strong> default level can be changed or you can reset <strong>the</strong>ir privilege level back to<br />

<strong>the</strong> default.<br />

• Assign <strong>the</strong> launch keyword (<strong>for</strong> example, configure) <strong>for</strong> <strong>the</strong> keyword’s command mode.<br />

• If you assign only <strong>the</strong> first keyword to <strong>the</strong> privilege level, all commands beginning with that keyword<br />

are also assigned to <strong>the</strong> privilege level. If you enter <strong>the</strong> entire command, <strong>the</strong> software assigns <strong>the</strong><br />

privilege level to that command only.<br />

To assign commands and passwords to a custom privilege level, you must be in privilege level 15 and use<br />

<strong>the</strong>se commands in <strong>the</strong> following sequence in <strong>the</strong> CONFIGURATION mode:<br />

Step Command Syntax Command Mode Purpose<br />

1 username name [access-class<br />

access-list-name] [privilege level]<br />

[nopassword | password<br />

[encryption-type] password]<br />

2<br />

enable password [level level]<br />

[encryption-mode] password<br />

CONFIGURATION Assign a user name and password.<br />

Configure <strong>the</strong> optional and required<br />

parameters:<br />

• name: Enter a text string.<br />

• access-class access-list-name: Enter <strong>the</strong><br />

name of a configured IP ACL.<br />

• privilege level range: 0 to 15.<br />

• nopassword: Do not require <strong>the</strong> user to<br />

enter a password.<br />

• encryption-type: Enter 0 <strong>for</strong> plain text or 7<br />

<strong>for</strong> encrypted text.<br />

• password: Enter a string.<br />

CONFIGURATION Configure a password <strong>for</strong> privilege level.<br />

Configure <strong>the</strong> optional and required<br />

parameters:<br />

• level level: Specify a level 0 to 15. Level<br />

15 includes all levels.<br />

• encryption-type: Enter 0 <strong>for</strong> plain text or 7<br />

<strong>for</strong> encrypted text.<br />

• password: Enter a string up to 25<br />

characters long.<br />

To change only <strong>the</strong> password <strong>for</strong> <strong>the</strong> enable<br />

command, configure only <strong>the</strong> password<br />

parameter.<br />

142 Security

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!