beautypg.com

Juniper Networks J-Series User Manual

Page 28

background image

Table 7: Permission Bits for Login Classes

Access

Permission Bit

Can view user account information in configuration mode and with the

show configuration

command.

admin

Can view user accounts and configure them (at the

[edit system login]

hierarchy level).

admin-control

Can view the access configuration in configuration mode and with the

show configuration

operational mode command.

access

Can view and configure access information (at the

[edit access]

hierarchy level).

access-control

Has all permissions.

all

Can clear (delete) information learned from the network that is stored in various network
databases (using the

clear

commands).

clear

Can enter configuration mode (using the

configure

command) and commit configurations

(using the

commit

command).

configure

Can perform all control-level operations (all operations configured with the

-control

permission bits).

control

Reserved for field (debugging) support.

field

Can view the firewall filter configuration in configuration mode.

firewall

Can view and configure firewall filter information (at the

[edit firewall]

hierarchy level).

firewall-control

Can read from and write to the removable media.

floppy

Can view the interface configuration in configuration mode and with the

show

configuration

operational mode command.

interface

Can view chassis, class of service, groups, forwarding options, and interfaces
configuration information. Can configure chassis, class of service, groups, forwarding
options, and interfaces (at the

[edit]

hierarchy).

interface-control

Can perform system maintenance, including starting a local shell on the router and
becoming the superuser in the shell (by issuing the

su root

command), and can halt and

reboot the router (using the

request system

commands).

maintenance

Can access the network by entering the

ping

,

ssh

,

telnet

, and

traceroute

commands.

network

Can restart software processes using the

restart

command and can configure whether

software processes are enabled or disabled (at the

[edit system processes]

hierarchy

level).

reset

Can use the

rollback

command to return to a previously committed configuration other

than the most recently committed one.

rollback

Can view general routing, routing protocol, and routing policy configuration information
in configuration and operational modes.

routing

6

User Authentication Overview

J-series™ Services Router Administration Guide