Wired Intelligent Edge

last person joined: 20 hours ago 

Bring performance and reliability to your network with the HPE Aruba Networking Core, Aggregation, and Access layer switches. Discuss the latest features and functionality of your switching devices, and find ways to improve security across your network to bring together a mobile-first solution
Expand all | Collapse all

new local user 2530

This thread has been viewed 22 times
  • 1.  new local user 2530

    Posted Oct 02, 2019 09:18 AM

    hi,

     

    Is it possible to add a new local user on an aruba 2530?

     

     



  • 2.  RE: new local user 2530

    Posted Oct 02, 2019 09:39 AM

    Try " mgmt-user <local username> <root | read-only> "

     

    It should then ask you for a password and re-verification of the password.

     

    This will be the password for the local user.

     

     

    --Give Kudos: found something helpful, important, or cool? Click Kudos Star in a post.
    --Problem Solved? Click "Accepted Solution" in a post.




  • 3.  RE: new local user 2530

    Posted Oct 02, 2019 09:42 AM

    invalid command..



  • 4.  RE: new local user 2530

    Posted Oct 02, 2019 09:45 AM

    Did you try it from the config mode?

     

    Example:

     

    (A_RAK)(config)# mgmt-user A_RAK root

     

     

    --Give Kudos: found something helpful, important, or cool? Click Kudos Star in a post.
    --Problem Solved? Click "Accepted Solution" in a post.





  • 5.  RE: new local user 2530

    Posted Oct 02, 2019 09:49 AM

    yes i did maybe it does not work on an aruba switch 2530



  • 6.  RE: new local user 2530

    Posted Oct 02, 2019 09:59 AM

    This should work

     

    aaa authentication local-user <username> // from config mode

     

     

    --Give Kudos: found something helpful, important, or cool? Click Kudos Star in a post.
    --Problem Solved? Click "Accepted Solution" in a post.



  • 7.  RE: new local user 2530

    Posted Oct 02, 2019 10:02 AM

    nope also does not work :( 



  • 8.  RE: new local user 2530

    Posted Oct 02, 2019 10:04 AM

    The full command is as follows.

     

    (config)#aaa authentication local-user <USER> group <groupname> password plaintext

     

    Refer to the security access guide for the command optimization and features. (Page 244)

     

    https://h20628.www2.hp.com/km-ext/kmcsdirect/emr_na-a00050234en_us-3.pdf

     

     

    --Give Kudos: found something helpful, important, or cool? Click Kudos Star in a post.
    --Problem Solved? Click "Accepted Solution" in a post.




  • 9.  RE: new local user 2530

    Posted Oct 02, 2019 10:08 AM

    yes i can add the user and log in but i have no rights to execute any commands



  • 10.  RE: new local user 2530

    MVP EXPERT
    Posted Oct 02, 2019 10:11 AM

    You can use the following, adjust accordingly (e.g Group, Plaintext etc).

     

    HP-2530-8G-PoEP(config)# aaa authentication local-user [test] group [operator] password plaintext
    New password for test: ********
    Please retype new password for test: ********


  • 11.  RE: new local user 2530

    Posted Oct 02, 2019 10:16 AM

    whats the command to add the local user to the manager role so i can do al the command via cli?



  • 12.  RE: new local user 2530

    Posted Oct 02, 2019 10:23 AM
    (config)#password manager user-name <name> plaintext



  • 13.  RE: new local user 2530

    Posted Oct 02, 2019 10:32 AM

    thats just a command to change the username for the manager user. I want to add a new local user with the same rights as a manager user.



  • 14.  RE: new local user 2530

    Posted Oct 02, 2019 10:51 AM
    A local user will not have write access.

    What you are asking is not possible AFAIK.

    If the intention here is to create a username and password for an administrator with write access.

    You could configure an operator with write access to your switch.



  • 15.  RE: new local user 2530

    Posted Apr 13, 2020 07:02 AM

    Hello A_RAK, 

     

    can you please explain me how do that? 

    Basically need to add more then one administrator on the switch. 

     

    Regards

    Antonello



  • 16.  RE: new local user 2530



  • 17.  RE: new local user 2530

    EMPLOYEE
    Posted Apr 13, 2020 07:23 AM

    Hi.

     

    You can try using the following command to add a new user:

     

    aaa authentication local-user admin-user group Level-15 password plaintext

     

    The group will define the user's permissions. Level-15 is one of the default groups available. You can create your own group if you need to assign different permissions to the user.

     

    Use the "show authorisation group" command to list the groups configurations.



  • 18.  RE: new local user 2530

    Posted Apr 13, 2020 04:58 PM

    Hello Minondas, 

     

    thx for the replay, I tried with the command and I got tos error: 

    Authorization group Level-15 does not exist.

     

    Here the result of sh authorization group:

     
     

    Local Management Groups - Authorization Information


    Group Name : default-security-group
    Group Privilege Level : 19

    Users
    ----------------
    admin-user

    Seq. Num. | Permission Rule Expression Log
    ---------- + ---------- ------------------------------------------ -------
    1 | Permit security-log Disable

     

    If I create a user with this group I can login, but I cannot issue any command. 

    How can I create a new privile-15 group?

     

    Regards

    Antonello



  • 19.  RE: new local user 2530

    EMPLOYEE
    Posted Apr 13, 2020 05:20 PM

    H amoneta,

     

    Try creating the group with the following commands?

     

    #aaa authorization group admin-group 10 match-command configure.* permit

    #aaa authorization group admin-group 20 match-command .* permit

     

     

     



  • 20.  RE: new local user 2530

    Posted Apr 14, 2020 04:52 PM

    Hello  LPcarvalho

     

     

     



  • 21.  RE: new local user 2530

    MVP GURU
    Posted Oct 02, 2019 03:10 PM

    or use a external server (like RADIUS or TACACS server)