share - getting hp comware 7 router to work with probono

564 views
Skip to first unread message

Patrick Ong

unread,
Jun 26, 2015, 5:37:59 AM6/26/15
to event-driv...@googlegroups.com
Cisco enable = Hp system-view.

But network-admin do not have system-view and network-operator is too restrictive.
So how?

I have a solution. Dont use Role, see my snippets below

<probono config snippet>

group = hp_comware_grp {
        default service = permit                                # permit all commands
        enable = crypt <your secret>

        service = shell {
                set priv-lvl = 15
                                                                        # permit all commands
                default cmd = permit
                default command = permit
                default attribute = permit
                optional cisco-av-pair="shell:roles*\"network-admin vsan-admin\""               # for MDS switches
        }

}

<working config snippet hp comware 7 x- not the  procurve series >
:: some work need to slim it down

line class vty
 authentication-mode scheme
 user-role level-14
 user-role network-admin
#
line aux 0
 user-role network-admin
#
line vty 0 63
 authentication-mode scheme
 user-role level-14
 user-role network-admin



hwtacacs scheme tacacs_auth
 primary authentication <your tacacs server> single-connection
 primary authorization <your tacacs server> single-connection
 primary accounting <your tacacs server> single-connection
 key authentication cipher <your secret>
 key authorization cipher <your secret>
 key accounting cipher <your secret>
 user-name-format without-domain
 nas-ip <VERY important field - the Source interface ip of your hp router that will AAA outbound/egress, else AAA will failed>
#
domain system
 authentication login hwtacacs-scheme tacacs_auth local
 authorization login hwtacacs-scheme tacacs_auth local
 accounting login hwtacacs-scheme tacacs_auth local
#
domain tacacs
 authentication login hwtacacs-scheme tacacs_auth local
 authorization login hwtacacs-scheme tacacs_auth local
 accounting login hwtacacs-scheme tacacs_auth local
#
 aaa session-limit ftp 32
 aaa session-limit telnet 32
 aaa session-limit http 32
 aaa session-limit ssh 32
 aaa session-limit https 32
 domain default enable system
#
 role default-role enable
#
role name level-0
 description Predefined level-0 role
#             
role name level-1
 description Predefined level-1 role
#
role name level-2
 description Predefined level-2 role
#
role name level-3
 description Predefined level-3 role
#
role name level-4
 description Predefined level-4 role
#
role name level-5
 description Predefined level-5 role
#
role name level-6
 description Predefined level-6 role
#
role name level-7
 description Predefined level-7 role
#
role name level-8
 description Predefined level-8 role
#
role name level-9
 description Predefined level-9 role
#
role name level-10
 description Predefined level-10 role
#
role name level-11
 description Predefined level-11 role
#
role name level-12
 description Predefined level-12 role
#
role name level-13
 description Predefined level-13 role
#
role name level-14
 description Predefined level-14 role
#
user-group system
#
local-user hptestaccount class manage
 password hash <your hash>
 service-type ssh telnet terminal
 authorization-attribute user-role network-admin
#
local-user user class manage
 service-type ssh telnet terminal
 authorization-attribute idle-cut 5
 authorization-attribute user-role network-admin


[HP-conn-BR24]display role
Role: network-admin
  Description: Predefined network admin role has access to all commands on the device
  VLAN policy: permit (default)
  Interface policy: permit (default)
  VPN instance policy: permit (default)
  Security zone policy: permit (default)
  -------------------------------------------------------------------
  Rule    Perm   Type  Scope         Entity                         
  -------------------------------------------------------------------
  sys-1   permit       command       *                              
  sys-2   permit RWX   xml-element   -                              
  sys-3   deny         command       display security-logfile summary
  sys-4   deny         command       system-view ; info-center securi
                                     ty-logfile directory *         
  sys-5   deny         command       security-logfile save          
  R:Read W:Write X:Execute

Role: network-operator
  Description: Predefined network operator role has access to all read commands on the device
  VLAN policy: permit (default)
  Interface policy: permit (default)
  VPN instance policy: permit (default)
  Security zone policy: permit (default)
  -------------------------------------------------------------------
  Rule    Perm   Type  Scope         Entity                         
  -------------------------------------------------------------------
  sys-1   permit       command       display *                      
  sys-2   permit       command       xml                            
  sys-3   deny         command       display history-command all    
  sys-4   deny         command       display exception *            
  sys-5   deny         command       display cpu-usage configuration
                                     *                              
  sys-6   deny         command       display kernel exception *     
  sys-7   deny         command       display kernel deadloop *      
  sys-8   deny         command       display kernel starvation *    
  sys-9   deny         command       display kernel reboot *        
  sys-10  deny         command       display memory trace *         
  sys-11  deny         command       display kernel memory *        
  sys-12  permit       command       system-view ; local-user *     
  sys-13  permit       command       system-view ; switchto mdc *   
  sys-14  permit R--   xml-element   -                              
  sys-15  deny         command       display security-logfile summary
  sys-16  deny         command       system-view ; info-center securi
                                     ty-logfile directory *         
  sys-17  deny         command       security-logfile save          
  R:Read W:Write X:Execute
              
Role: level-0
  Description: Predefined level-0 role
  VLAN policy: permit (default)
  Interface policy: permit (default)
  VPN instance policy: permit (default)
  Security zone policy: permit (default)
  -------------------------------------------------------------------
  Rule    Perm   Type  Scope         Entity                         
  -------------------------------------------------------------------
  sys-1   permit       command       tracert *                      
  sys-2   permit       command       telnet *                       
  sys-3   permit       command       ping *                         
  sys-4   permit       command       ssh2 *                         
  sys-5   permit       command       super *                        
  R:Read W:Write X:Execute

Role: level-1
  Description: Predefined level-1 role
  VLAN policy: permit (default)
  Interface policy: permit (default)
  VPN instance policy: permit (default)
  Security zone policy: permit (default)
  -------------------------------------------------------------------
  Rule    Perm   Type  Scope         Entity                         
  -------------------------------------------------------------------
  sys-1   permit       command       tracert *                      
  sys-2   permit       command       telnet *                       
  sys-3   permit       command       ping *                         
  sys-4   permit       command       ssh2 *                         
  sys-5   permit       command       display *                      
  sys-6   permit       command       super *                        
  sys-7   deny         command       display history-command all    
  R:Read W:Write X:Execute

Role: level-2
  Description: Predefined level-2 role
  VLAN policy: permit (default)
  Interface policy: permit (default)
  VPN instance policy: permit (default)
  Security zone policy: permit (default)

Role: level-3
  Description: Predefined level-3 role
  VLAN policy: permit (default)
  Interface policy: permit (default)
  VPN instance policy: permit (default)
  Security zone policy: permit (default)

Role: level-4
  Description: Predefined level-4 role
  VLAN policy: permit (default)
  Interface policy: permit (default)
  VPN instance policy: permit (default)
  Security zone policy: permit (default)

Role: level-5
  Description: Predefined level-5 role
  VLAN policy: permit (default)
  Interface policy: permit (default)
  VPN instance policy: permit (default)
  Security zone policy: permit (default)

Role: level-6
  Description: Predefined level-6 role
  VLAN policy: permit (default)
  Interface policy: permit (default)
  VPN instance policy: permit (default)
  Security zone policy: permit (default)
              
Role: level-7
  Description: Predefined level-7 role
  VLAN policy: permit (default)
  Interface policy: permit (default)
  VPN instance policy: permit (default)
  Security zone policy: permit (default)

Role: level-8
  Description: Predefined level-8 role
  VLAN policy: permit (default)
  Interface policy: permit (default)
  VPN instance policy: permit (default)
  Security zone policy: permit (default)

Role: level-9
  Description: Predefined level-9 role
  VLAN policy: permit (default)
  Interface policy: permit (default)
  VPN instance policy: permit (default)
  Security zone policy: permit (default)
  -------------------------------------------------------------------
  Rule    Perm   Type  Scope         Entity                         
  -------------------------------------------------------------------
  sys-1   permit RWX   feature       -                              
  sys-2   deny   RWX   feature       device                         
  sys-3   deny   RWX   feature       filesystem                     
  sys-4   permit       command       display *                      
  sys-5   deny         command       display history-command all    
  R:Read W:Write X:Execute

Role: level-10
  Description: Predefined level-10 role
  VLAN policy: permit (default)
  Interface policy: permit (default)
  VPN instance policy: permit (default)
  Security zone policy: permit (default)

Role: level-11
  Description: Predefined level-11 role
  VLAN policy: permit (default)
  Interface policy: permit (default)
  VPN instance policy: permit (default)
  Security zone policy: permit (default)

Role: level-12
  Description: Predefined level-12 role
  VLAN policy: permit (default)
  Interface policy: permit (default)
  VPN instance policy: permit (default)
  Security zone policy: permit (default)

Role: level-13
  Description: Predefined level-13 role
  VLAN policy: permit (default)
  Interface policy: permit (default)
  VPN instance policy: permit (default)
  Security zone policy: permit (default)

Role: level-14
  Description: Predefined level-14 role
  VLAN policy: permit (default)
  Interface policy: permit (default)
  VPN instance policy: permit (default)
  Security zone policy: permit (default)

Role: level-15
  Description: Predefined level-15 role
  VLAN policy: permit (default)
  Interface policy: permit (default)
  VPN instance policy: permit (default)
  Security zone policy: permit (default)
  -------------------------------------------------------------------
  Rule    Perm   Type  Scope         Entity                         
  -------------------------------------------------------------------
  sys-1   permit       command       *                              
  sys-2   permit RWX   xml-element   -                              
  sys-3   deny         command       display security-logfile summary
  sys-4   deny         command       system-view ; info-center securi
                                     ty-logfile directory *         
  sys-5   deny         command       security-logfile save          
  R:Read W:Write X:Execute

Role: security-audit
  Description: Predefined security audit role only has access to commands for the security log administrator
  VLAN policy: permit (default)
  Interface policy: permit (default)
  VPN instance policy: permit (default)
  Security zone policy: permit (default)
  -------------------------------------------------------------------
  Rule    Perm   Type  Scope         Entity                         
  -------------------------------------------------------------------
  sys-1   deny         command       *                              
  sys-2   permit       command       display security-logfile summary
  sys-3   permit       command       system-view ; info-center securi
                                     ty-logfile directory *         
  sys-4   permit       command       security-logfile save          
  sys-5   permit       command       cd *                           
  sys-6   permit       command       copy *                         
  sys-7   permit       command       delete *                       
  sys-8   permit       command       dir *                          
  sys-9   permit       command       mkdir *                        
  sys-10  permit       command       more *                         
  sys-11  permit       command       move *                         
  sys-12  permit       command       rmdir *                        
  sys-13  permit       command       pwd                            
  sys-14  permit       command       rename *                       
  sys-15  permit       command       undelete *                     
  sys-16  permit       command       ftp *                          
  sys-17  permit       command       sftp *                         
  sys-18  permit       command       virtual-ftp-append             
  sys-19  permit       command       virtual-ftp-ascii              
  sys-20  permit       command       virtual-ftp-binary             
  sys-21  permit       command       virtual-ftp-bye                
  sys-22  permit       command       virtual-ftp-cd                 
  sys-23  permit       command       virtual-ftp-cdup               
  sys-24  permit       command       virtual-ftp-close              
  sys-25  permit       command       virtual-ftp-delete             
  sys-26  permit       command       virtual-ftp-debug              
  sys-27  permit       command       virtual-ftp-dir                
  sys-28  permit       command       virtual-ftp-disconnect         
  sys-29  permit       command       virtual-ftp-get                
  sys-30  permit       command       virtual-ftp-help               
  sys-31  permit       command       virtual-ftp-lcd                
  sys-32  permit       command       virtual-ftp-ls                 
  sys-33  permit       command       virtual-ftp-mkdir              
  sys-34  permit       command       virtual-ftp-newer              
  sys-35  permit       command       virtual-ftp-open               
  sys-36  permit       command       virtual-ftp-passive            
  sys-37  permit       command       virtual-ftp-put                
  sys-38  permit       command       virtual-ftp-pwd                
  sys-39  permit       command       virtual-ftp-quit               
  sys-40  permit       command       virtual-ftp-reget              
  sys-41  permit       command       virtual-ftp-rstatus            
  sys-42  permit       command       virtual-ftp-rhelp              
  sys-43  permit       command       virtual-ftp-rename             
  sys-44  permit       command       virtual-ftp-reset              
  sys-45  permit       command       virtual-ftp-restart            
  sys-46  permit       command       virtual-ftp-rmdir              
  sys-47  permit       command       virtual-ftp-status             
  sys-48  permit       command       virtual-ftp-system             
  sys-49  permit       command       virtual-ftp-user               
  sys-50  permit       command       virtual-ftp-verbose            
  sys-51  permit       command       virtual-ftp-remove             
  sys-52  permit       command       virtual-ftp-exit               
  R:Read W:Write X:Execute

[HP-conn-BR24]     

[HP-conn-BR24]display version
HP Comware Software, Version 7.1.049, Release 0106P04
Copyright (c) 2010-2014 Hewlett-Packard Development Company, L.P.
HP MSR3024 uptime is 2 weeks, 3 days, 2 hours, 39 minutes
Last reboot reason : Power on
Boot image: cfa0:/msr3000-cmw710-boot-r0106p04.bin
Boot image version: 7.1.049P11, Release 0106P04
  Compiled Jul 30 2014 19:37:37
System image: cfa0:/msr3000-cmw710-system-r0106p04.bin
System image version: 7.1.049, Release 0106P04
  Compiled Jul 30 2014 19:37:37
Feature image(s) list:
  cfa0:/msr3000-cmw710-security-r0106p04.bin, version: 7.1.049
    Compiled Jul 30 2014 19:38:54
  cfa0:/msr3000-cmw710-voice-r0106p04.bin, version: 7.1.049
    Compiled Jul 30 2014 19:38:56
  cfa0:/msr3000-cmw710-data-r0106p04.bin, version: 7.1.049
    Compiled Jul 30 2014 19:39:01

CPU ID: 0x2
2G bytes DDR3 SDRAM Memory
8M bytes Flash Memory
PCB               Version:  2.0
CPLD              Version:  2.0
Basic    BootWare Version:  1.42
Extended BootWare Version:  1.42
[SLOT  0]AUX                       (Hardware)2.0,   (Driver)1.0,   (CPLD)2.0
[SLOT  0]GE0/0                     (Hardware)2.0,   (Driver)1.0,   (CPLD)2.0
[SLOT  0]GE0/1                     (Hardware)2.0,   (Driver)1.0,   (CPLD)2.0
[SLOT  0]GE0/2                     (Hardware)2.0,   (Driver)1.0,   (CPLD)2.0
[SLOT  0]CELLULAR0/0               (Hardware)2.0,   (Driver)1.0,   (CPLD)2.0
[SLOT  0]CELLULAR0/1               (Hardware)2.0,   (Driver)1.0,   (CPLD)2.0

[HP-conn-BR24] 


Reply all
Reply to author
Forward
0 new messages