Linux, FreeBSD, Juniper, Cisco / Network security articles and troubleshooting guides

FAQ
It is currently Fri Dec 01, 2023 3:01 pm


Author Message
mandrei99
Post  Post subject: Junos restricted user disallow "ping rapid" and "ping size" operational commands  |  Posted: Wed Jun 26, 2013 6:02 pm

Joined: Tue Aug 04, 2009 9:16 am
Posts: 250

Offline
 

Junos restricted user disallow "ping rapid" and "ping size" operational commands

The following Junos directive will block a Junos user from making use of "rapid" and "size" ping arguments on the CLI.

Code:
allow-commands = "(^show route)|(^show route .*)|(^quit)|(^ping ([^r|s]).+)|(^traceroute .*)|(^show bgp summary)"


And the outcome:
Code:
juniper@CORE_R1> ping ?
Possible completions:
  <host>               Hostname or IP address of remote host
  atm                  Ping remote Asynchronous Transfer Mode node
  bypass-routing       Bypass routing table, use specified interface
  count                Number of ping requests to send (1..2000000000 packets)
  detail               Display incoming interface of received packet
  do-not-fragment      Don't fragment echo request packets (IPv4)
  inet                 Force ping to IPv4 destination
  inet6                Force ping to IPv6 destination
  interface            Source interface (multicast, all-ones, unrouted packets)
  interval             Delay between ping requests (seconds)
  logical-system       Name of logical system
+ loose-source         Intermediate loose source route entry (IPv4)
  mpls                 Ping label-switched path
  no-resolve           Don't attempt to print addresses symbolically
  pattern              Hexadecimal fill pattern
  tos                  IP type-of-service value (0..255)
  ttl                  IP time-to-live value (IPv6 hop-limit value) (1..255 hops)
  verbose              Display detailed output
  vpls                 Ping VPLS MAC address
  wait                 Maximum wait time after sending final packet (seconds)


The drawback of this is that all arguments starting with "r" and "s" are left out by the regular expression.





Top
Display posts from previous:  Sort by  
E-mail friendPrint view

Topics related to - "Junos restricted user disallow "ping rapid" and "ping size" operational commands"
 Topics   Author   Replies   Views   Last post 
There are no new unread posts for this topic. Junos tacacs plus authentication for restricted privileges user with ping restrictions

admin

1

6099

Wed Jun 26, 2013 9:52 am

admin View the latest post

There are no new unread posts for this topic. Junos - How to limit arguments to ping CLI command

mandrei99

1

2815

Thu Jun 27, 2013 4:04 am

admin View the latest post

There are no new unread posts for this topic. Junos: ping: invalid routing instance `RI0'

mandrei99

0

5096

Fri Jan 03, 2014 10:11 am

mandrei99 View the latest post

There are no new unread posts for this topic. Junos: User 'remote' authenticated successfully but no local login-id configured

mandrei99

0

7443

Mon Jan 26, 2015 12:04 pm

mandrei99 View the latest post

There are no new unread posts for this topic. MTR / My traceroute in Junos

mandrei99

1

7144

Mon Oct 10, 2016 5:54 am

barrel View the latest post

There are no new unread posts for this topic. Juniper - Junos 11.4R8 based Olive

mandrei99

1

5735

Tue Jun 18, 2013 5:36 am

mandrei99 View the latest post

There are no new unread posts for this topic. Junos: How to show uncommitted changes and cancel them

mandrei99

1

37251

Wed Sep 25, 2013 7:31 am

mandrei99 View the latest post

There are no new unread posts for this topic. Junos: How to list routing table IDs

admin

0

3650

Sat Jan 17, 2015 3:53 pm

admin View the latest post

There are no new unread posts for this topic. Juniper SRX / Junos rescue configuration is not set

mandrei99

0

8309

Mon Feb 16, 2015 11:42 am

mandrei99 View the latest post

There are no new unread posts for this topic. How to search junos configuration option within cli help apropos

mandrei99

0

2733

Mon Jan 12, 2015 12:34 pm

mandrei99 View the latest post

 

Who is online
Users browsing this forum: No registered users and 0 guests
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum
Jump to:  
cronNews News Site map Site map SitemapIndex SitemapIndex RSS Feed RSS Feed Channel list Channel list


Delete all board cookies | The team | All times are UTC - 5 hours [ DST ]



phpBB SEO