Administrator Guide
Conguring Custom Privilege Levels
In addition to assigning privilege levels to the user, you can congure the privilege levels of commands so that they are visible in
dierent privilege levels.
Within the Dell Networking OS, commands have certain privilege levels. With the privilege command, you can change the
default level or you can reset their privilege level back to the default. Assign the launch keyword (for example, configure) for the
keyword’s command mode.
To assign commands and passwords to a custom privilege level, use the following commands. You must be in privilege level 15.
1. Assign a user name and password.
CONFIGURATION mode
username name [access-class access-list-name] [privilege level] [nopassword | password
[encryption-type] password] [secret]
Congure the optional and required parameters:
• name: enter a text string (up to 63 characters).
• access-class access-list-name: enter the name of a congured IP ACL.
• privilege level: the range is from 0 to 15.
• nopassword: do not require the user to enter a password.
• encryption-type: enter 0 for plain text or 7 for encrypted text.
• password: enter a text string.
• secret: specify the secret for the user.
2. Congure a password for privilege level.
CONFIGURATION mode
enable password [level level] [encryption-mode] password
Congure the optional and required parameters:
• level level: specify a level from 0 to 15. Level 15 includes all levels.
• encryption-type: enter 0 for plain text or 7 for encrypted text.
• password: enter a text string up to 32 characters long.
To change only the password for the enable command, congure only the password parameter.
3. Congure level and commands for a mode or reset a command’s level.
CONFIGURATION mode
privilege mode {level level command | reset command}
Congure the following required and optional parameters:
• mode: enter a keyword for the modes (exec, configure, interface, line, route-map, or router)
•
level level: the range is from 0 to 15. Levels 0, 1, and 15 are pre-congured. Levels 2 to 14 are available for custom
conguration.
• command: an Dell CLI keyword (up to ve keywords allowed).
• reset: return the command to its default privilege mode.
To view the conguration, use the show running-config command in EXEC Privilege mode.
The following example shows a conguration to allow a user john to view only EXEC mode commands and all snmp-server
commands. Because the snmp-server commands are enable level commands and, by default, found in CONFIGURATION mode,
also assign the launch command for CONFIGURATION mode,
configure, to the same privilege level as the snmp-server
commands.
Line 1: The user john is assigned privilege level 8 and assigned a password.
158
Security