Supported Platforms
Related Documentation
- EX, M, PTX, T Series
- user (Access)
- M, MX, PTX, QFX, T Series
- Overview of Template Accounts for RADIUS and TACACS+ Authentication
- QFX Series
- user (Access)
Configuring Local User Template Accounts for User Authentication
You use local user template accounts when you need different types of templates for authentication. Each template can define a different set of permissions appropriate for the group of users who use that template. These templates are defined locally on the router and referenced by the TACACS+ and RADIUS authentication servers.
When you configure local user templates and a user logs in, the Junos OS issues a request to the authentication server to authenticate the user’s login name. If a user is authenticated, the server returns the local username to the Junos OS, which then determines whether a local username is specified for that login name (local-username for TACACS+, Juniper-Local-User for RADIUS). If so, the Junos OS selects the appropriate local user template locally configured on the router. If a local user template does not exist for the authenticated user, the router defaults to the remote template.
To configure different access privileges for users who share the local user template account, include the allow-commands and deny-commands commands in the authentication server configuration file.
To configure a local user template, include the user local-username statement at the [edit system login] hierarchy level and specify the privileges you want to grant to the local users to whom the template applies:
This example configures the sales and engineering local user templates:
When the login users Simon and Rob are authenticated, the switch applies the sales local user template. When login users Harold and Jim are authenticated, the switch applies the engineering local user template.
Related Documentation
- EX, M, PTX, T Series
- user (Access)
- M, MX, PTX, QFX, T Series
- Overview of Template Accounts for RADIUS and TACACS+ Authentication
- QFX Series
- user (Access)
Published: 2013-08-15
Supported Platforms
Related Documentation
- EX, M, PTX, T Series
- user (Access)
- M, MX, PTX, QFX, T Series
- Overview of Template Accounts for RADIUS and TACACS+ Authentication
- QFX Series
- user (Access)