28.06.2014 Views

Discussion

Discussion

Discussion

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

eset -- Can reset/restart interfaces and daemons<br />

routing -- Can view routing configuration<br />

routing-control-- Can modify routing configuration<br />

shell -- Can start a local shell<br />

snmp -- Can view SNMP configuration<br />

snmp-control-- Can modify SNMP configuration<br />

system -- Can view system configuration<br />

system-control-- Can modify system configuration<br />

trace -- Can view trace file settings<br />

trace-control-- Can modify trace file settings<br />

view -- Can view current values and statistics<br />

maintenance -- Can become the super-user<br />

firewall -- Can view firewall configuration<br />

firewall-control-- Can modify firewall configuration<br />

secret -- Can view secret configuration<br />

secret-control-- Can modify secret configuration<br />

rollback -- Can rollback to previous configurations<br />

security -- Can view security configuration<br />

security-control-- Can modify security configuration<br />

access -- Can view access configuration<br />

access-control-- Can modify access configuration<br />

view-configuration-- Can view all configuration (not including secrets)<br />

Individual command authorization:<br />

Allow regular expression: none<br />

Deny regular expression: none<br />

Allow configuration regular expression: none<br />

Deny configuration regular expression: none<br />

Here is a user with operator privileges:<br />

mike@router1> show cli authorization<br />

Current user: 'mike' class 'operator'<br />

Permissions:<br />

clear -- Can clear learned network information<br />

network -- Can access the network<br />

reset -- Can reset/restart interfaces and daemons<br />

trace -- Can view trace file settings<br />

view -- Can view current values and statistics<br />

Individual command authorization:<br />

Allow regular expression: none<br />

Deny regular expression: none<br />

Allow configuration regular expression: none<br />

Deny configuration regular expression: none<br />

If you do not have permission to perform an operation, you are either “blind” to that<br />

operation or you see some type of indication that you cannot perform it. If you try to<br />

view the configuration without permission, you see the following warnings:<br />

aviva@router1> show configuration<br />

version /* ACCESS-DENIED */;<br />

system { /* ACCESS-DENIED */ };<br />

interfaces { /* ACCESS-DENIED */ };<br />

routing-options { /* ACCESS-DENIED */ };<br />

protocols { /* ACCESS-DENIED */ };<br />

policy-options { /* ACCESS-DENIED */ };<br />

92 | Chapter 2: Basic Router Security and Access Control<br />

This is the Title of the Book, eMatter Edition<br />

Copyright © 2008 O’Reilly & Associates, Inc. All rights reserved.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!