command-privileg - how to execute a command as a level 1 user

Created: Jul 18, 2018 18:14:12Latest reply: Aug 8, 2018 19:44:22 1265 10 1 0
Hello,

I activated for the level 1 user privilege this command so they can shutdown single ports and bring them up again:

<HUAWEI> system-view
[HUAWEI] command-privilege level 1 view gigabitethernet shutdown 

Now when I log into the cli with an level 1 privileg user, I cant find the command to shut down the ports.
Its not possible to enter into an interface like a level 15 privilege user for example to execute the shut down command.

How can I shut down now the ports with the level 1 users if they are granted to shutdown ports?

thanks in Advance
  • x
  • convention:

StarOfWest  Engager   Created Jul 19, 2018 15:09:18 Helpful(1) Helpful(1)

You need to do some extra configuration.
1. Define access to system view.
2. define interfaces for which you allow access.
3. define shutdown interface command, but pay attention whether is l2 or l3 interface.
4. define undo shutdown command, i believe you want level 1 user to activate the interface back :)

command-privilege level 1 view shell system-view
command-privilege level 1 view system interface GigabitEthernet0/0/1
command-privilege level 1 view system interface GigabitEthernet0/0/2
command-privilege level 1 view system interface GigabitEthernet0/0/3
command-privilege level 1 view gigabitethernet shutdown
command-privilege level 1 view gigabitethernet-l2 shutdown
command-privilege level 1 view gigabitethernet undo shutdown
command-privilege level 1 view gigabitethernet-l2 undo shutdown

Cheers!
  • x
  • convention:

“We only get answers to the questions that we ask.” physicist Werner Heisenberg
yoface     Created Jul 19, 2018 15:24:21 Helpful(0) Helpful(0)

Posted by StarOfWest at 2018-07-19 15:09 You need to do some extra configuration. 1. Define access to system view.2. define interfaces for wh ...
Cool thank you :)

Yes right I want to use level 1 user to shutdown ports.

My question is now, what is the command now which the level 1 user has to type in to shutdown ports on his cli session? command-privilege is not found with his permissions.

Thanks in advance
  • x
  • convention:

yoface     Created Jul 19, 2018 15:30:37 Helpful(0) Helpful(0)

And is it possible that the level 1 privilege users can login into the webinterface of the switch an shutdown ports there too?

What must I do so that the level 1 users can login into webinterface and only have permission to shutdown ethernet ports?
  • x
  • convention:

yoface     Created Jul 19, 2018 15:44:53 Helpful(0) Helpful(0)

Ah now it works :)

I missed before the command-privilege level 1 view gigabitethernet-l2 shutdown command

For what is the l2 standing for?

So the case is closed, thank you so much :)
  • x
  • convention:

yoface     Created Jul 19, 2018 15:55:29 Helpful(0) Helpful(0)

Sorry for spamming. The last final question is if it is possible too for level 1 privilege users to logon into webinterface and shutdown ports there too?
  • x
  • convention:

StarOfWest  Engager   Created Jul 20, 2018 13:54:31 Helpful(0) Helpful(0)

Gigabitethernet interface can work either in layer 2 or layer 3 (portswitch or undo portswitch). For layer 3 interface you have to define an IP address on the interface, for layer 2 you have to define the interface type as trunk, hybrid or access. Normally on routers you have layer 3 interfaces, and on switches layer 2 interfaces. That's why you need to run gigabitethernet-l2 command.

As for the web interface, i doubt it can be achieved, but you can have a try by setting the service-type for level 1 user as http.

<HUAWEI> system-view
[HUAWEI] aaa
[HUAWEI-aaa] local-user yoface service-type ssh telnet http

Basically for web user you can define 2 types of users - management user, which can do all the operations, and monitor user which can do only ping and monitoring.
See here additional details.
http://support.huawei.com/hedex/pages/EDOC1000161579DEG0801J/04/EDOC1000161579DEG0801J/04/resources/dc/dc_s_web_0e0151_1720.html?ft=0&fe=10&hib=11.5.1.8.1.8.1&id=dc_s_web_0e0151_1720&text=Administrator&docid=EDOC1000161579

if the question was resolved for CLI, please mark my reply as best answer.
You can try to open a new thread for web, but I doubt you can achieve the requirement.
  • x
  • convention:

“We only get answers to the questions that we ask.” physicist Werner Heisenberg
yoface     Created Jul 26, 2018 15:45:57 Helpful(0) Helpful(0)

Thank you so much, now I understand the differences.

I see its only possible to choose between management users and monitor users privilegs for the gui.

In my case I want a management user who can edit functions BUT can not overwrite the passwords of the other management users and admin.

I think thats not possible or?
  • x
  • convention:

StarOfWest  Engager   Created Aug 8, 2018 19:43:43 Helpful(0) Helpful(0)

it's best to open a new thread. Frankly I don't think it's possible, but, maybe somebody else knows it.
  • x
  • convention:

“We only get answers to the questions that we ask.” physicist Werner Heisenberg
StarOfWest  Engager   Created Aug 8, 2018 19:44:22 Helpful(0) Helpful(0)

regarding " how to execute a command as a level 1 user " please mark my answer as the best.
  • x
  • convention:

“We only get answers to the questions that we ask.” physicist Werner Heisenberg

Reply

Reply
You need to log in to reply to the post Login | Register

Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " Privacy."
If the attachment button is not available, update the Adobe Flash Player to the latest version!
Fast reply Scroll to top