29.04.2019 Views

OS6860(E)_AOS_8.1.1.R01_Switch_Management_Guide

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Managing <strong>Switch</strong> User Accounts<br />

Configuring Privileges for a User<br />

Configuring Privileges for a User<br />

To configure privileges for a user, enter the user command with the read-only or read-write option and<br />

the desired CLI command domain names or command family names. The read-only option provides<br />

access to show commands; the read-write option provides access to configuration commands and show<br />

commands. Command families are subsets of command domains.<br />

If you create a user without specifying any privileges, the user’s account will be configured with the privileges<br />

specified for the default user account.<br />

Command domains and families are listed here:<br />

Domain<br />

domain-admin<br />

domain-system<br />

domain-physical<br />

domain-network<br />

domain-layer2<br />

domain-service<br />

domain-policy<br />

domain-security<br />

Corresponding Families<br />

file telnet debug<br />

system aip snmp rmon webmgt config<br />

chassis module interface pmm health<br />

ip rip ospf bgp vrrp ip-routing ipx ipmr ipms rdp<br />

ospf3 ipv6<br />

vlan bridge stp 802.1q linkagg ip-helper<br />

dns<br />

qos policy slb<br />

session avlan aaa<br />

In addition to command families, the keywords all or none may be used to set privileges for all command<br />

families or no command families respectively.<br />

An example of setting up user privileges:<br />

-> user thomas read-write domain-network ip-helper telnet<br />

User thomas will have write access to all the configuration commands and show commands in the<br />

network domain, as well as Telnet and IP helper (DHCP relay) commands. The user will not be able to<br />

execute any other commands on the switch.<br />

Use the keyword all to specify access to all commands. In the following example, the user is given read<br />

access to all commands:<br />

-> user lindy read-only all<br />

Note. When modifying an existing user, the user password is not required. If you are configuring a new<br />

user with privileges, the password is required.<br />

The default user privileges may also be modified. See “Default User Settings” on page 6-7.<br />

Omni<strong>Switch</strong> <strong>AOS</strong> Release 8 <strong>Switch</strong> <strong>Management</strong> <strong>Guide</strong> May 2014 page 6-15

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!