Check Levels
This scenario shows how to configure different user-levels for operational commands.
Lower Command User Level
Description
This example demonstrates how to lower the permissions needed to execute a specific operational command.
Scenario
Step 1: Set the following configuration in DUT0 :
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set system login user teldat authentication encrypted-password '$6$SORHKuRjXep2genn$QHnsGGE26m5SV1GmSCaesYJDjXcyNZnHSzkn6Yq.MoJ8M0vq.txVdKXX7EuXkEVldAzyk2o3ySFdefYfKVW8b/' set system login user teldat role monitor
Step 2: Run the command show running on DUT0 and check whether the output contains the following tokens:
Insufficient privilegesShow output
CLI Error: Insufficient privileges
Step 3: Login as admin user on DUT0:
admin@osdx
Step 4: Modify the following configuration lines in DUT0 :
set user-level 0 command 'show running'
Step 5: Run the command show running on DUT0 and expect the following output:
Show output
# Teldat OSDx VM version v4.2.10.4 # Wed 16 Sep 2026 15:12:21 +00:00 # Warning: Configuration has not been saved set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set system login user teldat authentication encrypted-password '$6$SORHKuRjXep2genn$QHnsGGE26m5SV1GmSCaesYJDjXcyNZnHSzkn6Yq.MoJ8M0vq.txVdKXX7EuXkEVldAzyk2o3ySFdefYfKVW8b/' set system login user teldat role monitor set user-level 0 command 'show running'
Step 6: Login as admin user on DUT0:
admin@osdx
Raise Command User Level
Description
This example demonstrates how to raise the permissions needed to execute a specific operational command.
Scenario
Step 1: Set the following configuration in DUT0 :
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set system login user teldat authentication encrypted-password '$6$53u5DdTwuUeJcPpD$h2ll39zMwA7hYiMsEB52gLVmehE8GkJwTAhOlt3SNMrMO78xcZM59bYt/Qmy6hPpuOi366cJHdXZdRd5donYn0' set system login user teldat role monitor
Step 2: Run the command system login show users on DUT0 and expect the following output:
Show output
NAME LINE TIME COMMENT teldat ttyS0 2026-09-16 15:12
Step 3: Login as admin user on DUT0:
admin@osdx
Step 4: Modify the following configuration lines in DUT0 :
set user-level 15 command 'system login show users'
Step 5: Run the command show running on DUT0 and check whether the output contains the following tokens:
Insufficient privilegesShow output
CLI Error: Insufficient privileges
Step 6: Login as admin user on DUT0:
admin@osdx
Customize Multi-option Command
Description
This example demonstrates how to prohibit the use of some options in a specific operational command.
Scenario
Step 1: Set the following configuration in DUT0 :
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set system login user teldat authentication encrypted-password '$6$jhTB90VJr.EUujyY$z.VVluacnw5B0iPN6Uf.8s/jn127EA37Eka45nyRzbHlvhR6Jmvx2Z6Zi9/Hyo/0niFcaWF0LVJiVJE7uHyZi.' set system login user teldat role monitor
Step 2: Run the command system conntrack show protocol tcp on DUT0 and expect the following output:
Show output
conntrack v1.4.7 (conntrack-tools): 0 flow entries have been shown.
Step 3: Login as admin user on DUT0:
admin@osdx
Step 4: Modify the following configuration lines in DUT0 :
set user-level 15 command 'system conntrack show protocol <txt>'
Step 5: Run the command system conntrack show protocol tcp on DUT0 and check whether the output contains the following tokens:
Insufficient privilegesShow output
CLI Error: Insufficient privileges
Step 6: Login as admin user on DUT0:
admin@osdx
Customize File Pipe Command
Description
This example demonstrates how to lower the permissions needed to execute both the file pipe and the operational command.
Scenario
Step 1: Set the following configuration in DUT0 :
set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set system login user teldat authentication encrypted-password '$6$vhnm1v79dfp18y.i$dAn.CYiUpgPUfwjqHFoyXYNGzVQlrtUmQvMnuFncd6uEs3Xzd0iB9bcjht2j32P9T/ljL4.vLbjiZvGZEFS6i.' set system login user teldat role monitor
Step 2: Run the command system login show users | file on DUT0 and expect the following output:
Show output
Command's output saved under "support/system_login_show_users_2026-09-16-151255" Filesize: 153.000 B
Step 3: Login as admin user on DUT0:
admin@osdx
Step 4: Modify the following configuration lines in DUT0 :
set user-level 10 command file
Step 5: Run the command system login show users | file on DUT0 and check whether the output contains the following tokens:
Insufficient privilegesShow output
CLI Error: Insufficient privileges to use 'file' pipe CLI Error: Command error
Step 6: Login as admin user on DUT0:
admin@osdx