Provides instructions for configuring user profiles, groups, and access control rules to manage administrative privileges on the NCS 1004. These procedures allow administrators to enforce security policies through command and data restrictions while establishing reliable disaster-recovery credentials for emergency system access.
User profiles and privileges are authentication, authorization, and accounting (AAA) configurations that control access to System Admin configurations on the NCS 1004.
To create user profiles and assign privileges, you must
-
create user profiles with usernames and passwords for authentication,
-
specify command rules that define which commands users can execute,
-
specify data rules that control access to configuration data elements, and
-
apply these rules to user groups.
User authentication and authorization
You can use a username and a password for authentication. On successful authentication, you can execute commands and access data elements that are based on the command rules and data rules. Users who are part of a user group have access privileges to the system as defined in the command rules and data rules for that user group.
Use the show run aaa command in the System Admin Config mode to view existing AAA configurations.
Topics covered in this chapter
This chapter covers these topics:
-
Create a user profile: Create individual user accounts with authentication credentials.
-
Create a user group: Organize users into groups for easier privilege management.
-
Create command rules: Define which commands users can read and execute.
-
Create data rules: Control user access to configuration data elements.
-
Change disaster-recovery username and password: Configure emergency access credentials.
Create a user profile
Use this procedure to create a user profile to provide restricted access to the System Admin console based on assigned privileges.
Create a user group
Use this procedure to create a user group to associate command rules and data rules that are enforced on all users in the group.
Create command rules
Use this procedure to create command rules to permit or deny users in a user group from using certain commands.
Create data rules
Use this procedure to create data rules to permit or deny users in a user group from accessing and modifying configuration data elements.
Change disaster-recovery user name and password
Use this procedure to change the disaster-recovery user name and password to provide emergency access to the System Admin console.