05.01.2015 Views

MikroTik RouterOS™ v2.9

MikroTik RouterOS™ v2.9

MikroTik RouterOS™ v2.9

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

• password - policy that grants rights to change the password<br />

Notes<br />

There are three system groups which cannot be deleted:<br />

[admin@rb13] > /user group print<br />

0 name="read"<br />

policy=local,telnet,ssh,reboot,read,test,winbox,password,web,!ftp,!write,!policy<br />

1 name="write"<br />

policy=local,telnet,ssh,reboot,read,write,test,winbox,password,web,!ftp,!policy<br />

2 name="full"<br />

policy=local,telnet,ssh,ftp,reboot,read,write,policy,test,winbox,password,web<br />

3 name="test"<br />

policy=ssh,read,policy,!local,!telnet,!ftp,!reboot,!write,!test,!winbox,!password,!web<br />

[admin@rb13] ><br />

Exclamation sign '!' just before policy item name means NOT.<br />

Example<br />

To add reboot group that is allowed to reboot the router locally or using telnet, as well as read the<br />

router's configuration, enter the following command:<br />

[admin@rb13] user group> add name=reboot policy=telnet,reboot,read,local<br />

[admin@rb13] user group> print<br />

0 name="read"<br />

policy=local,telnet,ssh,reboot,read,test,winbox,password,web,!ftp,!write,!policy<br />

1 name="write"<br />

policy=local,telnet,ssh,reboot,read,write,test,winbox,password,web,!ftp,!policy<br />

2 name="full"<br />

policy=local,telnet,ssh,ftp,reboot,read,write,policy,test,winbox,password,web<br />

3 name="reboot"<br />

policy=local,telnet,reboot,read,!ssh,!ftp,!write,!policy,!test,!winbox,!password,!web<br />

[admin@rb13] user group><br />

Router Users<br />

Home menu level: /user<br />

Description<br />

Router user database stores the information such as username, password, allowed access addresses<br />

and group about router management personnel.<br />

Property Description<br />

address (IP address | netmask; default: 0.0.0.0/0) - host or network address from which the user is<br />

allowed to log in<br />

group (name) - name of the group the user belongs to<br />

name (name) - user name. Although it must start with an alphanumeric character, it may contain<br />

"*", "_", "." and "@" symbols<br />

Page 356 of 615<br />

Copyright 1999-2005, <strong>MikroTik</strong>. All rights reserved. Mikrotik, RouterOS and RouterBOARD are trademarks of Mikrotikls SIA.<br />

Other trademarks and registred trademarks mentioned herein are properties of their respective owners.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!