White Papers

Table Of Contents
Security
The commands in this chapter are available on Dell EMC Networking OS.
For configuration details, see the Security section in the Dell EMC Networking OS Configuration Guide.
NOTE: Dell EMC Networking OS implements LEAP with MSCHAP v2 supplicant.
Topics:
Role-Based Access Control Commands
AAA Accounting Commands
Authorization and Privilege Commands
Obscure Password Commands
Authentication and Password Commands
RADIUS Commands
TACACS+ Commands
Port Authentication (802.1X) Commands
SSH and SCP Commands
Secure DHCP Commands
ICMP Vulnerabilities
System Security Commands
Role-Based Access Control Commands
With Role-Based Access Control (RBAC), access and authorization is controlled based on a users role. Users are granted
permissions based on their user roles, not on their individual user ID. User roles are created for job functions and through those
roles they acquire the permissions to perform their associated job function.
This section describes the syntax and usage of RBAC-specific commands. You can find information on other related security
commands in this chapter:
aaa accounting
aaa authentication login
aaa authorization commands
authorization
show accounting
show users
username
aaa authorization role-only
Configure authentication to use the users role only when determining if access to commands is permitted.
Syntax
aaa authorization role-only
To return to the default setting, use the no aaa authentication role-only command.
Parameters
name
Enter a text string for the name of the user up to 63 characters. It cannot be one
of the system defined roles (sysadmin, secadmin, netadmin, netoperator).
inherit
existing-
role-name
Enter the inherit keyword then specify the system defined role to inherit
permissions from (sysadmin, secadmin, netadmin, netoperator).
Defaults none
48
1380 Security