34
Usage guidelines
The default user role feature assigns the default user role to AAA-authenticated users if the
authentication server (local or remote) does not assign any user roles to the users. These users are
allowed to access the system with the default user role.
If AAA users have been assigned user roles, they log in with the user roles.
If you do not specify the role-name argument, the default user role is network-operator.
Examples
# Enable the default user role feature.
<Sysname> system-view
[Sysname] role default-role enable
Related commands
role
role feature-group
Use role feature-group to create a user role feature group and enter its view, or enter the view of an
existing user role feature group.
Use undo role feature-group to delete a user role feature group.
Syntax
role feature-group name feature-group-name
undo role feature-group name feature-group-name
Default
Two user role feature groups L2 and L3 exist.
Views
System view
Predefined user roles
network-admin
Parameters
name feature-group-name: Specifies a feature group name. The feature-group-name argument is a
case-sensitive string of 1 to 31 characters.
Usage guidelines
The L2 feature group includes all Layer 2 feature commands, and the L3 feature group includes all
Layer 3 feature commands. These predefined feature groups are not user configurable.
In addition to the predefined feature groups L2 and L3, you can create a maximum of 64 user role
feature groups.
Examples
# Create feature group security-features and enter its view.
<Sysname> system-view
[Sysname] role feature-group name security-features
[Sysname-featuregrp-security-features]
Related commands
display role feature