15
Level Privile
e Descri
tion
1 Monitor
Involves commands for system maintenance and service fault diagnosis.
Commands at this level are not allowed to be saved after being configured. After
the switch is restarted, the commands at this level are restored to the default
settings.
Commands at this level include debugging, terminal, refresh, reset, and send.
2 System
Involves service configuration commands, such as routing configuration
commands and commands for configuring services at different network levels.
By default, commands at this level include all configuration commands except for
those at the manage level.
3 Manage
Involves commands that influence the basic operation of the system and
commands for configuring system support modules.
By default, commands at this level involve the configuration commands of file
system, FTP, TFTP, Xmodem download, user management, level setting, and
parameter settings within a system (which are not defined by any protocols or
RFCs).
Configuring a user privilege level
A user privilege level can be configured by using AAA authentication parameters or under a user interface.
Configuring user privilege level by using AAA authentication parameters
If the authentication mode of a user interface is scheme, the user privilege level of users logging into the user
interface is specified in AAA authentication configuration.
To configure the user privilege level by using AAA authentication parameters:
Ste
Command
Remarks
Enter system view system-view —
Enter user interface view
user-interface { first-num1
[ last-num1 ] | { aux | vty }
first-num2 [ last-num2 ] }
—
Specify the scheme authentication
mode
authentication-mode scheme
Required
By default, the authentication
mode for VTY users is password,
and no authentication is needed
for AUX login user.
Return to system view quit —
Configure the authentication mode
for SSH users as password
For more information about SSH,
see Security Configuration Guide.
Required if users use SSH to log in,
and username and password are
needed at authentication
Configure the
user privilege
level by using
AAA
authentication
Using local
authentication
• Use local-user to create a local
user and enter local user view.
• Use level keyword in the
authorization-attribute to
configure the user privilege
level.
Use either approach
• For local authentication, if you
do not configure the user
privilege level, the user
privilege level is 0.