渊羡,我需要LS-5560X-54F-EI的三权分立配置文档
问题描述:
我需要LS-5560X-54F-EI的三权分立配置文档,和基础配置指导
组网及组网描述:
啥是三权分立?
暂无
msr36
可以参考这个,命令和MSR的是通用的
#
配置账户角色
#
role name level-3
description Predefined level-3 role
rule 1 permit read write web-menu m_device/m_maintenance/m_changepassword
#
role name admin
description 系统管理
rule 1 permit read write execute feature
rule 2 permit read write execute web-menu
rule 3 deny read write execute web-menu m_monitor/
rule 4 deny read write execute web-menu m_resource/
rule 5 deny read write execute web-menu m_user/
rule 6 deny read write execute web-menu m_firewall/
rule 7 deny read write execute web-menu m_appsecurity/
rule 8 deny read write execute web-menu m_nat/
rule 9 deny read write execute web-menu m_vpn/
rule 10 deny read write execute web-menu m_loadbalance/
rule 11 deny read write execute web-menu m_network/
rule 12 deny read write execute web-menu m_secmonitor/
#
role name security-secret
description 安全保密管理
rule 1 permit read write execute feature
rule 2 permit read write execute web-menu
rule 3 deny read write execute web-menu m_dashboard/
rule 4 deny read write execute web-menu m_device/
rule 5 deny read write execute web-menu m_user/
rule 6 deny read write execute web-menu m_secmonitor/
#
配置三权账户
#
local-user admin class manage
service-type ftp
service-type telnet terminal https
authorization-attribute work-directory slot1#flash:
authorization-attribute user-role admin
password-control aging 7
password-control length 8
password-control composition type-number 3 type-length 1
password-control login-attempt 5 exceed lock-time 10
#
local-user audit class manage
service-type telnet terminal https
authorization-attribute user-role security-audit
password-control aging 7
password-control length 8
password-control composition type-number 3 type-length 1
password-control login-attempt 5 exceed lock-time 10
#
local-user secret class manage
service-type telnet terminal https
authorization-attribute work-directory slot1#flash:
authorization-attribute user-role level-3
authorization-attribute user-role security-secret
password-control aging 7
password-control length 8
password-control composition type-number 3 type-length 1
password-control login-attempt 5 exceed lock-time 10
#
使能HTTPS管理及WebUI日志功能
#
ip https enable
webui log enable
暂无
你正在,我需要LS-5560X-54F-EI的三权分立配置文档
版权声明:本文由CRM小助手整理收集与网络,仅供学习交流使用,不代表CRM论坛观点。如有侵权,请联系我们,我们将及时删除处理。
CRM论坛投稿:投稿地址
CRM论坛(CRMBBS.COM)始办于2019年,是致力于CRM实施方案、免费CRM软件、SCRM系统、客户管理系统的垂直内容社区网站,CRM论坛持续专注于CRM领域,在不断深化理解CRM系统的同时,进一步利用新型互联网技术,为用户实现企业、客户、合作伙伴与产品之间的无缝连接与交互。