Dell C9000 Series Networking Configuration Manual page 972

Hide thumbs Also See for C9000 Series:
Table of Contents

Advertisement

defined roles. Otherwise you would have to create a user role's command permissions from scratch. You
then restrict commands or add commands to that role. For more information about this topic, see
Modifying Command Permissions for
NOTE:
You can change user role permissions on system pre-defined user roles or user-defined user roles.
Important Points to Remember
Consider the following when creating a user role:
Only the system administrator and user-defined roles inherited from the system administrator can
create roles and user names. Only the system administrator, security administrator, and roles inherited
from these can use the "role" command to modify command permissions. The security administrator
and roles inherited by security administrator can only modify permissions for commands they already
have access to.
Make sure you select the correct role you want to inherit.
If you inherit a user role, you cannot modify or delete the inheritance. If you want to change or remove
the inheritance, delete the user role and create it again. If the user role is in use, you cannot delete the
user role.
1
Create a new user role
CONFIGURATION mode
userrole name [inherit existing-role-name]
2
Verify that the new user role has inherited the security administrator permissions.
Dell(conf)#do show userroles
EXEC Privilege mode
3
After you create a user role, configure permissions for the new user role. See
Modifying Command Permissions for
Example of Creating a User Role
The configuration in the following example creates a new user role, myrole, which inherits the security
administrator (secadmin) permissions.
Create a new user role, myrole and inherit security administrator permissions.
Dell(conf)#userrole myrole inherit secadmin
Verify that the user role, myrole, has inherited the security administrator permissions. The output highlighted
in bold indicates that the user role has successfully inherited the security administrator permissions.
Dell(conf)#do show userroles
************* Mon Apr 28 14:46:25 PDT 2014 **************
Authorization Mode:
Role
Inheritance
netoperator
netadmin
secadmin
sysadmin
MAC.
Roles.
Roles.
role or privilege
Modes
Exec Config Interface Router IP Route-map Protocol MAC
Exec Config Line
Exec Config Interface Line Router IP Route-map Protocol
Security
972

Advertisement

Table of Contents
loading

Table of Contents