Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Enjoy members-only rewards and discounts
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.

Dell Configuration Guide for the S4048–ON System 9.14.2.4

PDF

Modifying Command Permissions for Roles

You can modify (add or delete) command permissions for newly created user roles and system defined roles using the role mode { { { addrole | deleterole } role-name } | reset } command command in Configuration mode.

NOTE You cannot modify system administrator command permissions.

If you add or delete command permissions using the role command, those changes only apply to the specific user role. They do not apply to other roles that have inheritance from that role. Authorization and accounting only apply to the roles specified in that configuration.

When you modify a command for a role, you specify the role, the mode, and whether you want to restrict access using the deleterole keyword or grant access using the addrole keyword followed by the command you are controlling access.

The following output displays the modes available for the role command.

DellEMC(conf)#role  ?
configure            Global configuration mode               
exec                 Exec Mode                               
interface            Interface configuration mode            
line                 Line Configuration mode                 
route-map            Route map configuration mode            
router               Router configuration mode           

Examples: Deny Network Administrator from Using the show users Command.

The following example denies the netadmin role from using the show users command and then verifies that netadmin cannot access the show users command in exec mode. Note that the netadmin role is not listed in the Role access: secadmin,sysadmin, which means the netadmin cannot access the show users command.

DellEMC(conf)#role exec deleterole netadmin show users

DellEMC#show role mode exec show users
Role access: secadmin,sysadmin

Example: Allow Security Administrator to Configure Spanning Tree

The following example allows the security administrator (secadmin) to configure the spanning tree protocol. Note command is protocol spanning-tree.
DellEMC(conf)#role configure addrole secadmin protocol spanning-tree 

Example: Allow Security Administrator to Access Interface Mode

The following example allows the security administrator (secadmin) to access Interface mode.
DellEMC(conf)#role configure addrole secadmin ?
LINE       Initial keywords of the command to modify
DellEMC(conf)#role configure addrole secadmin interface 

Example: Allow Security Administrator to Access Only 10-Gigabit Ethernet Interfaces

The following example allows the security administrator (secadmin) to only access 10-Gigabit Ethernett interfaces and then shows that the secadmin, highlighted in bold, can now access Interface mode. However, the secadmin can only access 10-Gigabit Ethernet interfaces.
DellEMC(conf)#role configure addrole secadmin ?
LINE            Initial keywords of the command to modify
DellEMC(conf)#role configure addrole secadmin interface tengigabitethernet

DellEMC(conf)#show role mode configure interface
Role access: netadmin, secadmin, sysadmin

Example: Verify that the Security Administrator Can Access Interface Mode

The following example shows that the secadmin role can now access Interface mode (highlighted in bold).

Role        Inheritance  Modes                                             
netoperator                                                                              
netadmin                 Exec Config Interface Router IP RouteMap Protocol MAC 
secadmin                 Exec Config Interface Line                               
sysadmin                 Exec Config Interface Line Router IP RouteMap Protocol MAC

Example: Remove Security Administrator Access to Line Mode.

The following example removes the secadmin access to LINE mode and then verifies that the security administrator can no longer access LINE mode, using the show role mode configure line command in EXEC Privilege mode.

DellEMC(conf)#role configure deleterole secadmin ?
LINE          Initial keywords of the command to modify
DellEMC(conf)#role configure deleterole secadmin line 

DellEMC(conf)#do show role mode ?
configure   					Global configuration mode               
exec                  Exec Mode                               
interface             Interface configuration mode            
line                  Line Configuration mode                 
route-map             Route map configuration mode            
router                Router configuration mode   

DellEMC(conf)#do show role mode configure line
Role access:sysadmin

Example: Grant and Remove Security Administrator Access to Configure Protocols

By default, the system defined role, secadmin, is not allowed to configure protocols. The following example first grants the secadmin role to configure protocols and then removes access to configure protocols. 
DellEMC(conf)#role configure addrole secadmin protocol
DellEMC(conf)#role configure deleterole secadmin protocol

Example: Resets Only the Security Administrator role to its original setting.

The following example resets only the secadmin role to its original setting. 

DellEMC(conf)#no role configure addrole secadmin protocol 

Example: Reset System-Defined Roles and Roles that Inherit Permissions

In the following example the command protocol permissions are reset to their original setting or one or more of the system-defined roles and any roles that inherited permissions from them.
DellEMC(conf)#role configure reset protocol

Rate this content

Accurate
Useful
Easy to understand
Was this article helpful?
0/3000 characters
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please select whether the article was helpful or not.
  Comments cannot contain these special characters: <>()\