Information
All login classes should have permissions defined.
Rationale:
Controlling the level of access which users are granted when logging into a router, helps protect against both malicious attacks and accidental misconfiguration of the router by less experienced staff. Login classes should be defined to grant permissions to user accounts, both local and remote, allowing permissions to be managed in a similar manner to User Groups on a Microsoft Windows system.
All Custom Login classes should have one more permissions defined which will be applied to all users, local and remote, linked to the class.
Solution
Configure the Permissions for a class using the following command under the [edit system login] hierarchy:
[edit system login]
user@host#set class <class name> permissions <permission or list of permissions>
Default Value:
No permissions are defined by default.