Cisco enable = Hp system-view.
But network-admin do not have system-view and network-operator is too restrictive.
So how?
I have a solution. Dont use Role, see my snippets below
<probono config snippet>
group = hp_comware_grp {
default service = permit # permit all commands
enable = crypt <your secret>
service = shell {
set priv-lvl = 15
# permit all commands
default cmd = permit
default command = permit
default attribute = permit
optional cisco-av-pair="shell:roles*\"network-admin vsan-admin\"" # for MDS switches
}
}
<working config snippet hp comware 7 x- not the procurve series >
:: some work need to slim it down
line class vty
authentication-mode scheme
user-role level-14
user-role network-admin
#
line aux 0
user-role network-admin
#
line vty 0 63
authentication-mode scheme
user-role level-14
user-role network-admin
hwtacacs scheme tacacs_auth
primary authentication <your tacacs server> single-connection
primary authorization <your tacacs server> single-connection
primary accounting <your tacacs server> single-connection
key authentication cipher <your secret>
key authorization cipher <your secret>
key accounting cipher <your secret>
user-name-format without-domain
nas-ip <VERY important field - the Source interface ip of your hp router that will AAA outbound/egress, else AAA will failed>
#
domain system
authentication login hwtacacs-scheme tacacs_auth local
authorization login hwtacacs-scheme tacacs_auth local
accounting login hwtacacs-scheme tacacs_auth local
#
domain tacacs
authentication login hwtacacs-scheme tacacs_auth local
authorization login hwtacacs-scheme tacacs_auth local
accounting login hwtacacs-scheme tacacs_auth local
#
aaa session-limit ftp 32
aaa session-limit telnet 32
aaa session-limit http 32
aaa session-limit ssh 32
aaa session-limit https 32
domain default enable system
#
role default-role enable
#
role name level-0
description Predefined level-0 role
#
role name level-1
description Predefined level-1 role
#
role name level-2
description Predefined level-2 role
#
role name level-3
description Predefined level-3 role
#
role name level-4
description Predefined level-4 role
#
role name level-5
description Predefined level-5 role
#
role name level-6
description Predefined level-6 role
#
role name level-7
description Predefined level-7 role
#
role name level-8
description Predefined level-8 role
#
role name level-9
description Predefined level-9 role
#
role name level-10
description Predefined level-10 role
#
role name level-11
description Predefined level-11 role
#
role name level-12
description Predefined level-12 role
#
role name level-13
description Predefined level-13 role
#
role name level-14
description Predefined level-14 role
#
user-group system
#
local-user hptestaccount class manage
password hash <your hash>
service-type ssh telnet terminal
authorization-attribute user-role network-admin
#
local-user user class manage
service-type ssh telnet terminal
authorization-attribute idle-cut 5
authorization-attribute user-role network-admin
[HP-conn-BR24]display role
Role: network-admin
Description: Predefined network admin role has access to all commands on the device
VLAN policy: permit (default)
Interface policy: permit (default)
VPN instance policy: permit (default)
Security zone policy: permit (default)
-------------------------------------------------------------------
Rule Perm Type Scope Entity
-------------------------------------------------------------------
sys-1 permit command *
sys-2 permit RWX xml-element -
sys-3 deny command display security-logfile summary
sys-4 deny command system-view ; info-center securi
ty-logfile directory *
sys-5 deny command security-logfile save
R:Read W:Write X:Execute
Role: network-operator
Description: Predefined network operator role has access to all read commands on the device
VLAN policy: permit (default)
Interface policy: permit (default)
VPN instance policy: permit (default)
Security zone policy: permit (default)
-------------------------------------------------------------------
Rule Perm Type Scope Entity
-------------------------------------------------------------------
sys-1 permit command display *
sys-2 permit command xml
sys-3 deny command display history-command all
sys-4 deny command display exception *
sys-5 deny command display cpu-usage configuration
*
sys-6 deny command display kernel exception *
sys-7 deny command display kernel deadloop *
sys-8 deny command display kernel starvation *
sys-9 deny command display kernel reboot *
sys-10 deny command display memory trace *
sys-11 deny command display kernel memory *
sys-12 permit command system-view ; local-user *
sys-13 permit command system-view ; switchto mdc *
sys-14 permit R-- xml-element -
sys-15 deny command display security-logfile summary
sys-16 deny command system-view ; info-center securi
ty-logfile directory *
sys-17 deny command security-logfile save
R:Read W:Write X:Execute
Role: level-0
Description: Predefined level-0 role
VLAN policy: permit (default)
Interface policy: permit (default)
VPN instance policy: permit (default)
Security zone policy: permit (default)
-------------------------------------------------------------------
Rule Perm Type Scope Entity
-------------------------------------------------------------------
sys-1 permit command tracert *
sys-2 permit command telnet *
sys-3 permit command ping *
sys-4 permit command ssh2 *
sys-5 permit command super *
R:Read W:Write X:Execute
Role: level-1
Description: Predefined level-1 role
VLAN policy: permit (default)
Interface policy: permit (default)
VPN instance policy: permit (default)
Security zone policy: permit (default)
-------------------------------------------------------------------
Rule Perm Type Scope Entity
-------------------------------------------------------------------
sys-1 permit command tracert *
sys-2 permit command telnet *
sys-3 permit command ping *
sys-4 permit command ssh2 *
sys-5 permit command display *
sys-6 permit command super *
sys-7 deny command display history-command all
R:Read W:Write X:Execute
Role: level-2
Description: Predefined level-2 role
VLAN policy: permit (default)
Interface policy: permit (default)
VPN instance policy: permit (default)
Security zone policy: permit (default)
Role: level-3
Description: Predefined level-3 role
VLAN policy: permit (default)
Interface policy: permit (default)
VPN instance policy: permit (default)
Security zone policy: permit (default)
Role: level-4
Description: Predefined level-4 role
VLAN policy: permit (default)
Interface policy: permit (default)
VPN instance policy: permit (default)
Security zone policy: permit (default)
Role: level-5
Description: Predefined level-5 role
VLAN policy: permit (default)
Interface policy: permit (default)
VPN instance policy: permit (default)
Security zone policy: permit (default)
Role: level-6
Description: Predefined level-6 role
VLAN policy: permit (default)
Interface policy: permit (default)
VPN instance policy: permit (default)
Security zone policy: permit (default)
Role: level-7
Description: Predefined level-7 role
VLAN policy: permit (default)
Interface policy: permit (default)
VPN instance policy: permit (default)
Security zone policy: permit (default)
Role: level-8
Description: Predefined level-8 role
VLAN policy: permit (default)
Interface policy: permit (default)
VPN instance policy: permit (default)
Security zone policy: permit (default)
Role: level-9
Description: Predefined level-9 role
VLAN policy: permit (default)
Interface policy: permit (default)
VPN instance policy: permit (default)
Security zone policy: permit (default)
-------------------------------------------------------------------
Rule Perm Type Scope Entity
-------------------------------------------------------------------
sys-1 permit RWX feature -
sys-2 deny RWX feature device
sys-3 deny RWX feature filesystem
sys-4 permit command display *
sys-5 deny command display history-command all
R:Read W:Write X:Execute
Role: level-10
Description: Predefined level-10 role
VLAN policy: permit (default)
Interface policy: permit (default)
VPN instance policy: permit (default)
Security zone policy: permit (default)
Role: level-11
Description: Predefined level-11 role
VLAN policy: permit (default)
Interface policy: permit (default)
VPN instance policy: permit (default)
Security zone policy: permit (default)
Role: level-12
Description: Predefined level-12 role
VLAN policy: permit (default)
Interface policy: permit (default)
VPN instance policy: permit (default)
Security zone policy: permit (default)
Role: level-13
Description: Predefined level-13 role
VLAN policy: permit (default)
Interface policy: permit (default)
VPN instance policy: permit (default)
Security zone policy: permit (default)
Role: level-14
Description: Predefined level-14 role
VLAN policy: permit (default)
Interface policy: permit (default)
VPN instance policy: permit (default)
Security zone policy: permit (default)
Role: level-15
Description: Predefined level-15 role
VLAN policy: permit (default)
Interface policy: permit (default)
VPN instance policy: permit (default)
Security zone policy: permit (default)
-------------------------------------------------------------------
Rule Perm Type Scope Entity
-------------------------------------------------------------------
sys-1 permit command *
sys-2 permit RWX xml-element -
sys-3 deny command display security-logfile summary
sys-4 deny command system-view ; info-center securi
ty-logfile directory *
sys-5 deny command security-logfile save
R:Read W:Write X:Execute
Role: security-audit
Description: Predefined security audit role only has access to commands for the security log administrator
VLAN policy: permit (default)
Interface policy: permit (default)
VPN instance policy: permit (default)
Security zone policy: permit (default)
-------------------------------------------------------------------
Rule Perm Type Scope Entity
-------------------------------------------------------------------
sys-1 deny command *
sys-2 permit command display security-logfile summary
sys-3 permit command system-view ; info-center securi
ty-logfile directory *
sys-4 permit command security-logfile save
sys-5 permit command cd *
sys-6 permit command copy *
sys-7 permit command delete *
sys-8 permit command dir *
sys-9 permit command mkdir *
sys-10 permit command more *
sys-11 permit command move *
sys-12 permit command rmdir *
sys-13 permit command pwd
sys-14 permit command rename *
sys-15 permit command undelete *
sys-16 permit command ftp *
sys-17 permit command sftp *
sys-18 permit command virtual-ftp-append
sys-19 permit command virtual-ftp-ascii
sys-20 permit command virtual-ftp-binary
sys-21 permit command virtual-ftp-bye
sys-22 permit command virtual-ftp-cd
sys-23 permit command virtual-ftp-cdup
sys-24 permit command virtual-ftp-close
sys-25 permit command virtual-ftp-delete
sys-26 permit command virtual-ftp-debug
sys-27 permit command virtual-ftp-dir
sys-28 permit command virtual-ftp-disconnect
sys-29 permit command virtual-ftp-get
sys-30 permit command virtual-ftp-help
sys-31 permit command virtual-ftp-lcd
sys-32 permit command virtual-ftp-ls
sys-33 permit command virtual-ftp-mkdir
sys-34 permit command virtual-ftp-newer
sys-35 permit command virtual-ftp-open
sys-36 permit command virtual-ftp-passive
sys-37 permit command virtual-ftp-put
sys-38 permit command virtual-ftp-pwd
sys-39 permit command virtual-ftp-quit
sys-40 permit command virtual-ftp-reget
sys-41 permit command virtual-ftp-rstatus
sys-42 permit command virtual-ftp-rhelp
sys-43 permit command virtual-ftp-rename
sys-44 permit command virtual-ftp-reset
sys-45 permit command virtual-ftp-restart
sys-46 permit command virtual-ftp-rmdir
sys-47 permit command virtual-ftp-status
sys-48 permit command virtual-ftp-system
sys-49 permit command virtual-ftp-user
sys-50 permit command virtual-ftp-verbose
sys-51 permit command virtual-ftp-remove
sys-52 permit command virtual-ftp-exit
R:Read W:Write X:Execute
[HP-conn-BR24]
[HP-conn-BR24]display version
HP Comware Software, Version 7.1.049, Release 0106P04
Copyright (c) 2010-2014 Hewlett-Packard Development Company, L.P.
HP MSR3024 uptime is 2 weeks, 3 days, 2 hours, 39 minutes
Last reboot reason : Power on
Boot image: cfa0:/msr3000-cmw710-boot-r0106p04.bin
Boot image version: 7.1.049P11, Release 0106P04
Compiled Jul 30 2014 19:37:37
System image: cfa0:/msr3000-cmw710-system-r0106p04.bin
System image version: 7.1.049, Release 0106P04
Compiled Jul 30 2014 19:37:37
Feature image(s) list:
cfa0:/msr3000-cmw710-security-r0106p04.bin, version: 7.1.049
Compiled Jul 30 2014 19:38:54
cfa0:/msr3000-cmw710-voice-r0106p04.bin, version: 7.1.049
Compiled Jul 30 2014 19:38:56
cfa0:/msr3000-cmw710-data-r0106p04.bin, version: 7.1.049
Compiled Jul 30 2014 19:39:01
CPU ID: 0x2
2G bytes DDR3 SDRAM Memory
8M bytes Flash Memory
PCB Version: 2.0
CPLD Version: 2.0
Basic BootWare Version: 1.42
Extended BootWare Version: 1.42
[SLOT 0]AUX (Hardware)2.0, (Driver)1.0, (CPLD)2.0
[SLOT 0]GE0/0 (Hardware)2.0, (Driver)1.0, (CPLD)2.0
[SLOT 0]GE0/1 (Hardware)2.0, (Driver)1.0, (CPLD)2.0
[SLOT 0]GE0/2 (Hardware)2.0, (Driver)1.0, (CPLD)2.0
[SLOT 0]CELLULAR0/0 (Hardware)2.0, (Driver)1.0, (CPLD)2.0
[SLOT 0]CELLULAR0/1 (Hardware)2.0, (Driver)1.0, (CPLD)2.0
[HP-conn-BR24]