
Multilevel Access
308659-14.10 Rev 01
A-3
• If the user name is not Manager or User, and RADIUS is enabled, the name/
password pair is checked on the configured RADIUS server. If a match is
found, access is granted at the assigned privilege level. For more detailed
information about enabling RADIUS, see Configuring RADIUS.
• If the user name is not Manager or User, and RADIUS is not enabled (or no
match is found), the name/password pair is checked in the MIB of the device.
If a match is found, access is granted at the assigned privilege level.
• If none of these scenarios produces a match to the name/password pair, or if
both the Access object and RADIUS are disabled, access is denied and the
user is prompted for a new name/password pair.
Access Privileges
A user’s privilege level determines the system commands a user can execute. In
addition to the existing manager and user privilege levels, a third level, that of
operator, has been added. A manager privilege level account allows you to enter
any system command and allows read-write access to the device configuration. An
operator privilege level account allows you to execute most system commands,
and allows limited access to the device configuration. A user privilege level
account allows user level system commands and allows read-only access to the
device configuration.
If you attempt to execute a command that requires a higher privilege level an error
message will occur. For example, if a user privilege level account attempts to
execute a manager privilege level command the following error is displayed:
[1:1]$
bcc
bcc#
config
Insufficient privilege
access#
To assign access privileges, assign the user to a group (or create and assign the
user to a new group) that has the desired privilege level. For a list of system
commands and the privilege level required to execute them, refer to Appendix B,
“System Commands.”
Comentarios a estos manuales