12.07.2015 Views

BROCADE IP PRIMER

BROCADE IP PRIMER

BROCADE IP PRIMER

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

User Access ControlUser Access ControlOn most switches, it is a good idea to have at least some form of passwordprotection. After all, you don't want just anyone making changes to yourswitches, right?Usernames and PasswordsSimply put, a username and password are a combination that you can defineto allow certain individuals to access your switch. A username can be anything.A password can be anything. But the combination of the two is what permitsyou to access the switch. Typically, you'll want your passwords to be cryptic (difficultto guess). A combination of letters, numbers, and special characters(periods, commas, etc.) is a good idea.The Three “Enable” ModesTo start with, every switch should have an “enable” password. As we've talkedabout earlier in this chapter, this is the password that will get you into “PrivilegedEXEC mode.” This gives you full access to the switch to make changes,read tables, etc.But what if you want to give someone Privileged EXEC mode access, but youwant to limit what they can do? Brocade provides three “enable” passwordsthat you can define:Super-User. This is the king. With this password, you have full control to executeany commands on the switch. Typically, this should be your most crypticpassword, and should be used only by Administrators.Port-Configuration. This allows a user access to most “show” commands, andit allows the user to make changes to individual interfaces. It does not allowthe user to make global changes to the switch (i.e., Global config mode).Read-Only. This allows a user to access most “show” commands, but it doesnot allow any changes to be made. This is typically used for other non-administrativepersonnel who may need to troubleshoot network throughput, butshould not be allowed to make changes.To configure these passwords, you can use the following commands:Switch#conf tSwitch(config)#enable super-user-password s0m3th1ngh4rdSwitch(config)#enable port-config-password admins-0nlySwitch(config)#enable read-only-password EasyPasswordSwitch(config)#Brocade <strong>IP</strong> Primer 141

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!