Comware

 View Only
last person joined: yesterday 

Expand all | Collapse all

User Roles - 'enable' equivalent in CW7

This thread has been viewed 5 times
  • 1.  User Roles - 'enable' equivalent in CW7

    Posted May 25, 2023 09:53 AM

    With Comware 5 devices we are able to setup a local user with basic read access to the device and then use 'su' to change to full admin rights after a suitable password is entered akin to the *cough* Cisco 'enable' mode.
    How on earth do I do this in CW7? If I grant a user the 'network-operator' role they don't have permission to issue the 'su' command. If I grant the 'network-admin' role they have full access from the start. The system only uses local users on the device so no TACACS or RADIUS involved. I am sure I am missing something simple but CW7 seems to have made simple functionality overly complicated and has me stumped!
    TIA
    Zac



  • 2.  RE: User Roles - 'enable' equivalent in CW7
    Best Answer

    Posted May 26, 2023 02:21 AM

    Hi Zac,

    in CMW7 the complete AAA Section has been redesigned. So you have now 16 levels for Access Control. You can enter the command display role to show the predefined roles and access rights and of course you can change them. To achieve a similar behavior as it was in CMW5 you have to create a user with authorization-attribute user-role level-1 (network-operator is not permitted to enter super-command) and set the command: super password role network-admin simple <PWD>.

    Best regards,
    Marco.




  • 3.  RE: User Roles - 'enable' equivalent in CW7

    Posted May 26, 2023 04:42 AM

    Thanks Marco that brilliant. Knew I was missing something simple!
    Best regards,
    Zac