Cisco SFS7000P-SK9 Command Reference - Page 111

Usage Guidelines, username, password, super, secret

Page 111 highlights

Chapter 2 Administrative Commands username Usage Guidelines Platform Availability: Cisco SFS 3001, Cisco SFS 7000, Cisco SFS 7008, Cisco SFS 3012, Cisco 4x InfiniBand Switch Module for IBM BladeCenter Privilege Level: Unrestricted read-write user or general read-write user (change own password only). The username command • Creates and remove user accounts. The default CLI user accounts are guest, admin, and super. • Changes user password. A user with read-write access may change their own password. • Assigns access levels based upon functional areas, such as Fibre Channel, Ethernet, and InfiniBand administrative areas. Access levels may be unrestricted or read-only or read-write for the various administrative areas. Unrestricted indicates super user. • Enables or disables the account. • Associates user accounts with SNMP community strings. This community string serves as the password for Element Manager access. You must create the user account with the password keyword before you can configure the account. By default, the Server Switch provides the unrestricted user login super (that uses a default password of super). This login uses secret as its default SNMP community string. SNMP community strings provide the user credentials necessary to access Management Information Base (MIB) object. Each user login uses one unique community string and one password. A login must use a community string to launch an Element Manager session. To restrict a deny a user access to SNMP, do not provide the login with a community string. Note SNMP community strings are sent across the network in UDP packets with no encryption. By default, new user accounts have read-only access. You may grant write privileges to a user for functional areas, such as InfiniBand, Ethernet, and Fibre Channel. Privileges are order-dependent. You must enter multiple access privileges in the following order: 1. ib-ro 2. ib-rw 3. ip-ethernet-ro 4. ip-ethernet-rw 5. fc-ro 6. fc-rw 7. unrestricted-rw When changing the privileges of an existing user, specify all the privileges allowed to the user (including re-entering existing privileges) because the privilege argument removes all existing privileges and replaces them with them with the new ones. OL-9163-02 Cisco SFS 7000 Series Product Family Command Reference Guide 2-81

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404

2-81
Cisco SFS 7000 Series Product Family Command Reference Guide
OL-9163-02
Chapter 2
Administrative Commands
username
Usage Guidelines
Platform Availability:
Cisco SFS 3001, Cisco SFS 7000, Cisco SFS 7008, Cisco SFS 3012, Cisco 4x InfiniBand Switch Module
for IBM BladeCenter
Privilege Level:
Unrestricted read-write user or general read-write user (change own password only).
The
username
command
Creates and remove user accounts. The default CLI user accounts are guest, admin, and super.
Changes user password. A user with read-write access may change their own password.
Assigns access levels based upon functional areas, such as Fibre Channel, Ethernet, and InfiniBand
administrative areas. Access levels may be unrestricted or read-only or read-write for the various
administrative areas. Unrestricted indicates super user.
Enables or disables the account.
Associates user accounts with SNMP community strings. This community string serves as the
password for Element Manager access.
You must create the user account with the
password
keyword before you can configure the account. By
default, the Server Switch provides the unrestricted user login
super
(that uses a default password of
super
). This login uses
secret
as its default SNMP community string. SNMP community strings provide
the user credentials necessary to access Management Information Base (MIB) object.
Each user login uses one unique community string and one password. A login must use a community
string to launch an Element Manager session. To restrict a deny a user access to SNMP, do not provide
the login with a community string.
Note
SNMP community strings are sent across the network in UDP packets with no encryption.
By default, new user accounts have read-only access. You may grant write privileges to a user for
functional areas, such as InfiniBand, Ethernet, and Fibre Channel. Privileges are order-dependent. You
must enter multiple access privileges in the following order:
1.
ib-ro
2.
ib-rw
3.
ip-ethernet-ro
4.
ip-ethernet-rw
5.
fc-ro
6.
fc-rw
7.
unrestricted-rw
When changing the privileges of an existing user, specify all the privileges allowed to the user (including
re-entering existing privileges) because the privilege argument removes all existing privileges and
replaces them with them with the new ones.