Template:Networking rutos manual users: Difference between revisions
No edit summary |
No edit summary |
||
(41 intermediate revisions by 7 users not shown) | |||
Line 1: | Line 1: | ||
{{ | ==={{#switch:{{{series}}}|TAP100|TAP200=User 'admin' settings|#default=Change Password}}=== | ||
---- | |||
| | The <b>User settings</b> section is used to change the password of the current user. | ||
= | [[File:Networking_rutos_users_change_password_v3.png|border|class=tlt-border]] | ||
The <b>Users</b> | {{#switch:{{{series}}}|TAP100|TAP200=|#default= ===System Users=== | ||
---- | |||
====Summary==== | |||
---- | |||
The <b>System Users</b> page is used to add new user accounts that can access the device with different user credentials than the default ones. The newly added users can be assigned to one of two groups, either of which can be modified to limit WebUI read/write access rights for users belonging to each specific group. | |||
<b>This page is unrelated to SSH users.</b> By default, there is one SSH user named "root" and it shares the same password as the default WebUI user named "admin". | <b>This page is unrelated to SSH users.</b> By default, there is one SSH user named "root" and it shares the same password as the default WebUI user named "admin". | ||
This manual page provides an overview of the Users | This manual page provides an overview of the Users page in {{{name}}} devices. | ||
{{Template:Networking_rutos_manual_basic_advanced_webui_disclaimer}} | {{Template:Networking_rutos_manual_basic_advanced_webui_disclaimer | ||
| series = {{{series}}} | |||
}} | |||
====Groups==== | |||
---- | |||
The <b>Groups</b> section lists available user groups of which there are three: | The <b>Groups</b> section lists available user groups of which there are three: | ||
[[File: | [[File:Networking_rutos_users_groups_v2.png|border|class=tlt-border]] | ||
---- | ---- | ||
<ul> | <ul> | ||
Line 26: | Line 31: | ||
<li>additional users cannot be added to this group;</li> | <li>additional users cannot be added to this group;</li> | ||
<li>access rights for this group cannot be modified.</li> | <li>access rights for this group cannot be modified.</li> | ||
</ul><br>[[File: | </ul><br>[[File:Networking_rutos_manual_users_root_visualization.png]] | ||
</li> | </li> | ||
---- | ---- | ||
Line 33: | Line 38: | ||
<li>limited read access; by default, users belonging to this group cannot view these pages: | <li>limited read access; by default, users belonging to this group cannot view these pages: | ||
<ul> | <ul> | ||
<li>System → [[{{{name}}} | <li>System → [[{{{name}}}_Administration#System_Users|Users]].</li> | ||
</ul> | </ul> | ||
</li> | </li> | ||
<li>unlimited write access by default;</li> | <li>unlimited write access by default;</li> | ||
<li>access rights can be modified.</li> | <li>access rights can be modified.</li> | ||
</ul><br>[[File: | </ul><br>[[File:Networking_rutos_manual_users_admin_visualization.png]] | ||
</li> | </li> | ||
---- | ---- | ||
Line 46: | Line 51: | ||
<li>limited read access; by default, users belonging to this group cannot view these pages: | <li>limited read access; by default, users belonging to this group cannot view these pages: | ||
<ul> | <ul> | ||
<li>Services → Mobile Utilities → Messages → [[{{{name}}} Mobile_Utilities#Send_Messages|Send Messages]];</li> | {{#ifeq:{{{mobile}}}|0||<li>Services → Mobile Utilities → Messages → [[{{{name}}} Mobile_Utilities#Send_Messages|Send Messages]];</li>}} | ||
<li>System → [[{{{name}}} | <li>System → [[{{{name}}}_Administration#System_Users|Users]];</li> | ||
<li>System → [[{{{name}}} Firmware|Firmware]];</li> | <li>System → [[{{{name}}} Firmware|Firmware]];</li> | ||
<li>System → [[{{{name}}} Reboot|Reboot]].</li> | <li>System → [[{{{name}}} Reboot|Reboot]].</li> | ||
Line 53: | Line 58: | ||
</li> | </li> | ||
<li>access rights can be modified.</li> | <li>access rights can be modified.</li> | ||
</ul><br>[[File: | </ul><br>[[File:Networking_rutos_manual_users_user_visualization.png]] | ||
</li> | </li> | ||
</ul> | </ul> | ||
Line 59: | Line 64: | ||
<b>Additional note</b>: you can view and/or edit settings for each group by clicking the 'Edit' button next to them. More on information on how to edit group access settings is located in the following section of this manual page. | <b>Additional note</b>: you can view and/or edit settings for each group by clicking the 'Edit' button next to them. More on information on how to edit group access settings is located in the following section of this manual page. | ||
===Group Settings (edit group)=== | =====Group Settings (edit group)===== | ||
---- | ---- | ||
A group's parameters can be set in its <b>Group Settings</b> page. To access the Groups Settings page, click the 'Edit' button next to the group's name. Below is an example of the Group Settings section: | A group's parameters can be set in its <b>Group Settings</b> page. To access the Groups Settings page, click the 'Edit' button next to the group's name. Below is an example of the Group Settings section: | ||
[[File: | [[File:Networking_rutos_users_groups_group_settings_v2.png|border|class=tlt-border]] | ||
<table class="nd-mantable"> | <table class="nd-mantable"> | ||
<tr> | <tr> | ||
<th>Field</th> | <th>Field</th> | ||
<th>Value</th> | <th style="width:300px">Value</th> | ||
<th>Description</th> | <th>Description</th> | ||
</tr> | </tr> | ||
<tr> | <tr> | ||
<td>Write action</td> | <td>Write action</td> | ||
<td>Allow | <td>Allow {{!}} Deny; default: <b>Allow</b></td> | ||
<td>Specifies whether to allow | <td>Specifies whether to deny or allow write access for users belonging the group.</td> | ||
</tr> | </tr> | ||
<tr> | <tr> | ||
<td>Write access</td> | <td>Write access</td> | ||
<td>path(s) to page(s); default: <b> | <td>path(s) to page(s); default: <b> | ||
<td> | <ul> | ||
<li><b>System > Administration > User Settings > Change Password</b></li> | |||
</ul> | |||
</b></td> | |||
<td>Controls the ability of users to change and execute the contents (e.g. Network > Lan).</td> | |||
</tr> | </tr> | ||
<tr> | <tr> | ||
<td>Read action</td> | <td>Read action</td> | ||
<td>Allow | <td>Allow {{!}} Deny; default: <b>Deny</b></td> | ||
<td>Specifies whether to allow | <td>Specifies whether to deny or allow read access for users belonging the group.</td> | ||
</tr> | </tr> | ||
<tr> | <tr> | ||
<td>Read access</td> | <td>Read access</td> | ||
<td>path(s) to page(s); default: | |||
< | <ul> | ||
<li><b>System > Administration > User Settings > System Users</b></li> | |||
<li><b>System > Firmware</b></li> | |||
<li><b>System > Maintenance > Backup</b></li> | |||
<li><b>System > Administration > Access Control</b></li> | |||
</ul> | <li><b>System > Maintenance > CLI</b></li> | ||
<li><b>System > Maintenance > Custom Scripts</b></li> | |||
<td>Path(s) to the page(s) to which the selected "Read action" will be applied. Click the plus symbol to add | <li><b>System > Maintenance > Troubleshoot</b></li> | ||
<li><b>System > Package Manager</b></li> | |||
<li><b>Network</b></li> | |||
<li><b>System > Setup Wizard</b></li> | |||
{{#ifeq:{{{wifi}}}|1|<li><b>Status > Wireless > Channel Analysis</b></li>}} | |||
{{#ifeq:{{{wifi}}}|1|<li><b>Services > Hotspot > General > Userscripts</b></li>}} | |||
{{#ifeq:{{{mobile}}}|1|<li><b>Services > Mobile Utilities > Messages > Send Messages</b></li>}} | |||
</ul> | |||
</td> | |||
<td>Path(s) to the page(s) to which the selected "Read action" will be applied. Click the plus symbol to add more entries.</td> | |||
</tr> | </tr> | ||
</table> | </table> | ||
====Examples==== | ======Examples====== | ||
---- | ---- | ||
The easiest way to master the syntax is to navigate to page that you want to generate a path for and the copy the path from the URL of that page. | The easiest way to master the syntax is to navigate to page that you want to generate a path for and the copy the path from the URL of that page. | ||
For example, to specify the path to the | For example, to specify the path to the Network → Mobile page, navigate to the page, copy the page's URL address <b>starting from the symbol "#"</b> and paste it into one of the access fields: | ||
[[File: | [[File:Networking_rutos_users_groups_example_url_bar_v1.png]] | ||
---- | ---- | ||
However, the VPN window contains links to many different types of VPN pages. If you want to specify only one of them, you can do it as well. For example, to to specify the path to the IPsec page, <b>add "/ipsec" to the path string</b>: | However, the VPN window contains links to many different types of VPN pages. If you want to specify only one of them, you can do it as well. For example, to to specify the path to the IPsec page, <b>add "/ipsec" to the path string</b>: | ||
services/vpn<b>/ipsec</b> | |||
---- | ---- | ||
An <b>asterisk (*)</b> in the path string means that the every page from that point on is included in that path. For example, to generate a path that includes pages in the Services menu tab: | An <b>asterisk (*)</b> in the path string means that the every page from that point on is included in that path. For example, to generate a path that includes pages in the Services menu tab: | ||
services/<b>*</b> | |||
Or to simply include everything in the entire WebUI (<b>if this path is combined with <i>Read action: Deny</i>, users from that group will not be able to login to the WebUI</b>): | Or to simply include everything in the entire WebUI (<b>if this path is combined with <i>Read action: Deny</i>, users from that group will not be able to login to the WebUI</b>): | ||
Line 120: | Line 138: | ||
<b>*</b> | <b>*</b> | ||
==Users== | ====Users==== | ||
---- | |||
The <b>Users</b> section lists all created users and provides the possibility to change their passwords and the group they belong to (with the exception of the default user "admin" which always belongs to the <i>root</i> group). | The <b>Users</b> section lists all created users and provides the possibility to change their passwords and the group they belong to (with the exception of the default user "admin" which always belongs to the <i>root</i> group). | ||
By default, there is only one user called "admin": | By default, there is only one user called "admin": | ||
[[File: | [[File:Networking_rutos_users_users_v3.png|border|class=tlt-border]] | ||
===User Settings (edit user)=== | =====User Settings (edit user)===== | ||
---- | ---- | ||
Each user's password and group parameters can be set in their <b>User Settings</b> pages. To access the User Settings page, click the 'Edit' button next to the user's name. | Each user's password and group parameters can be set in their <b>User Settings</b> pages. To access the User Settings page, click the 'Edit' button next to the user's name. | ||
Line 134: | Line 152: | ||
<u>However</u>, you may want to add a new user at first. This can be done from the [[{{{name}}}_Users#Add_New_User|Add New User]] section below: | <u>However</u>, you may want to add a new user at first. This can be done from the [[{{{name}}}_Users#Add_New_User|Add New User]] section below: | ||
[[File: | [[File:Networking_rutos_users_add_new_user_example_v3.png|border|class=tlt-border]] | ||
<ol> | <ol> | ||
Line 145: | Line 163: | ||
Below is an example of a newly added user's settings page: | Below is an example of a newly added user's settings page: | ||
[[File: | [[File:Networking_rutos_users_user_settings_v3.png|border|class=tlt-border]] | ||
<table class="nd-mantable"> | <table class="nd-mantable"> | ||
Line 157: | Line 175: | ||
<td>string; default: <b>none</b></td> | <td>string; default: <b>none</b></td> | ||
<td>Displays the user's name.</td> | <td>Displays the user's name.</td> | ||
</tr> | </tr> | ||
<tr> | <tr> | ||
<td>New password</td> | <td>New password</td> | ||
<td>string; default: <b>none</b></td> | <td>string; default: <b>none</b></td> | ||
<td>Create a new password for the user. The password must contain at least 8 characters, including at least one upper case letter and one digit.</td> | <td><li>Create a new password for the user. The password must contain at least 8 characters, including at least one upper case letter and one digit.</li><li>Another option is to use the 'Dice' icon, which generates random passwords.</li></td> | ||
</tr> | </tr> | ||
<tr> | <tr> | ||
Line 175: | Line 188: | ||
<tr> | <tr> | ||
<td>Group</td> | <td>Group</td> | ||
<td>admin | <td>admin {{!}} user; default: <b>user</b></td> | ||
<td>The group to which the user belongs.</td> | <td>The group to which the user belongs.</td> | ||
</tr> | |||
<tr> | |||
<td>Enable SSH access</td> | |||
<td>off {{!}} on; default: <b>off</b></td> | |||
<td>Enables SSH access (only for 'root' users).</td> | |||
</tr> | </tr> | ||
</table> | </table> | ||
==Add New User== | ====Add New User==== | ||
---- | |||
The <b>Add New User</b> section is used to create additional users that can access the WebUI. After a new user is added, it will appear in the [[{{{name}}} Users#Users|Users]] section. | The <b>Add New User</b> section is used to create additional users that can access the WebUI. After a new user is added, it will appear in the [[{{{name}}} Users#Users|Users]] section. | ||
[[File: | [[File:Networking_rutos_users_add_new_user_v3.png|border|class=tlt-border]] | ||
<table class="nd-mantable"> | <table class="nd-mantable"> | ||
Line 200: | Line 218: | ||
<td>Password</td> | <td>Password</td> | ||
<td>string; default: <b>none</b></td> | <td>string; default: <b>none</b></td> | ||
<td>A password for the new user. The password must contain at least 8 characters, including at least one upper case letter and one digit.</td> | <td><li>A password for the new user. The password must contain at least 8 characters, including at least one upper case letter and one digit.</li><li>Another option is to use the 'Dice' icon, which generates random passwords.</li></td> | ||
</tr> | </tr> | ||
</table> | </table>}} | ||
Revision as of 10:29, 27 August 2024
Change Password
The User settings section is used to change the password of the current user.
System Users
Summary
The System Users page is used to add new user accounts that can access the device with different user credentials than the default ones. The newly added users can be assigned to one of two groups, either of which can be modified to limit WebUI read/write access rights for users belonging to each specific group.
This page is unrelated to SSH users. By default, there is one SSH user named "root" and it shares the same password as the default WebUI user named "admin".
This manual page provides an overview of the Users page in {{{name}}} devices.
If you're having trouble finding this page or some of the parameters described here on your device's WebUI, you should turn on "Advanced WebUI" mode. You can do that by clicking the "Advanced" button, located at the top of the WebUI.
Groups
The Groups section lists available user groups of which there are three:
- root - highest level of authority. Key elements that define this group:
- has unlimited read/write access;
- additional users cannot be added to this group;
- access rights for this group cannot be modified.
- admin - second highest level of authority. Key elements that define this group:
- limited read access; by default, users belonging to this group cannot view these pages:
- System → [[{{{name}}}_Administration#System_Users|Users]].
- unlimited write access by default;
- access rights can be modified.
- limited read access; by default, users belonging to this group cannot view these pages:
- user - lowest level of authority. Key elements that define this group:
- no write access;
- limited read access; by default, users belonging to this group cannot view these pages:
- Services → Mobile Utilities → Messages → [[{{{name}}} Mobile_Utilities#Send_Messages|Send Messages]];
- System → [[{{{name}}}_Administration#System_Users|Users]];
- System → [[{{{name}}} Firmware|Firmware]];
- System → [[{{{name}}} Reboot|Reboot]].
- access rights can be modified.
Additional note: you can view and/or edit settings for each group by clicking the 'Edit' button next to them. More on information on how to edit group access settings is located in the following section of this manual page.
Group Settings (edit group)
A group's parameters can be set in its Group Settings page. To access the Groups Settings page, click the 'Edit' button next to the group's name. Below is an example of the Group Settings section:
Field | Value | Description |
---|---|---|
Write action | Allow | Deny; default: Allow | Specifies whether to deny or allow write access for users belonging the group. |
Write access | path(s) to page(s); default:
|
Controls the ability of users to change and execute the contents (e.g. Network > Lan). |
Read action | Allow | Deny; default: Deny | Specifies whether to deny or allow read access for users belonging the group. |
Read access | path(s) to page(s); default:
|
Path(s) to the page(s) to which the selected "Read action" will be applied. Click the plus symbol to add more entries. |
Examples
The easiest way to master the syntax is to navigate to page that you want to generate a path for and the copy the path from the URL of that page.
For example, to specify the path to the Network → Mobile page, navigate to the page, copy the page's URL address starting from the symbol "#" and paste it into one of the access fields:
However, the VPN window contains links to many different types of VPN pages. If you want to specify only one of them, you can do it as well. For example, to to specify the path to the IPsec page, add "/ipsec" to the path string:
services/vpn/ipsec
An asterisk (*) in the path string means that the every page from that point on is included in that path. For example, to generate a path that includes pages in the Services menu tab:
services/*
Or to simply include everything in the entire WebUI (if this path is combined with Read action: Deny, users from that group will not be able to login to the WebUI):
*
Users
The Users section lists all created users and provides the possibility to change their passwords and the group they belong to (with the exception of the default user "admin" which always belongs to the root group).
By default, there is only one user called "admin":
User Settings (edit user)
Each user's password and group parameters can be set in their User Settings pages. To access the User Settings page, click the 'Edit' button next to the user's name.
However, you may want to add a new user at first. This can be done from the [[{{{name}}}_Users#Add_New_User|Add New User]] section below:
- create a username;
- create a password for the user (must contain at least 8 characters, including at least one upper case letter and one digit);
- click the 'Add' button;
- click the 'Edit' next to newly added user.
Below is an example of a newly added user's settings page:
Field | Value | Description |
---|---|---|
Username | string; default: none | Displays the user's name. |
New password | string; default: none | |
Confirm new password | string; default: none | Repeat the new password. |
Group | admin | user; default: user | The group to which the user belongs. |
Enable SSH access | off | on; default: off | Enables SSH access (only for 'root' users). |
Add New User
The Add New User section is used to create additional users that can access the WebUI. After a new user is added, it will appear in the [[{{{name}}} Users#Users|Users]] section.
Field | Value | Description |
---|---|---|
Username | string; default: none | A custom name for the new user. |
Password | string; default: none |