четверг, 24 января 2013 г.

Role-Based CLI Access

R1(config)#aaa new-model 
R1(config)#enable secret cisco
R1#enable view
 Password:
R1#%PARSER-6-VIEW_SWITCH: successfully set to view 'root'.


R1#conf t
R1(config)#parser view SHOWVIEW
 
R1(config-view)#%PARSER-6-VIEW_CREATED: view 'SHOWVIEW' successfully created.
R1(config-view)#secret ciscoshowview
R1(config-view)#commands exec include all show
R1(config-view)#exit


R1(config)#parser view RELOADPINGVIEW
R1(config-view)#%PARSER-6-VIEW_CREATED: view 'RELOADPINGVIEW' successfully created.
R1(config-view)#secret pingreloadcisco
R1(config-view)#commands exec include all ping
R1(config-view)#commands exec include all reload
R1(config-view)#exit


R1(config)#parser view USERSHOW superview
R1(config-view)#secret ciscoshowsuperview
R1(config-view)#view SHOWVIEW
R1(config-view)#exit



R1(config)#parser view USERPINGRELOAD superview
R1(config-view)#secret ciscoreloadsuperview
R1(config-view)#view
RELOADPINGVIEW 

R1(config-view)#exit

 
R1(config)#username adminshow view USERSHOW secret cisco1
R1(config)#username adminpingreload view
RELOADPINGVIEW secret cisco2
R1(config)#aaa authentication login default local
R1(config)#aaa authorization exec default local
R1(config)#aaa authorization console
R1(config)#exit

Комментариев нет:

Отправить комментарий