You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

华为路由器Ansible Playbook执行失败:无法提升至特权模式

解决Ansible连接华为路由器执行display current-configuration失败的问题

错误原因分析

报错信息显示无法将权限提升至特权模式,当前设备处于用户视图(Huawei>),而display current-configuration命令需要在**特权视图(Huawei#)**下执行;同时Ansible默认的特权提升逻辑不匹配华为设备的命令规则,导致触发"无法识别命令"的错误。


解决方案步骤

1. 确认华为设备的特权提升命令

华为设备从用户视图进入特权视图,通常使用super命令(部分旧版本设备支持enable),需确保设备已配置特权密码。

2. 配置Ansible特权提升参数

在Playbook或Inventory文件中添加特权提升相关配置,让Ansible自动完成视图切换:

  • become: yes:启用特权提升
  • become_method: super(若设备用enable则替换为该值)
  • become_password: <你的特权密码>

3. 指定华为设备的网络OS类型

Ansible需要明确设备系统类型以适配命令逻辑,添加ansible_network_os: huawei.huawei_vrp(需提前安装华为官方集合)。


修改后的完整Playbook示例

---
- name: Master node
  hosts: huawei_node
  vars:
    max_retries: 4
  connection: network_cli
  gather_facts: false
  # 特权提升配置
  become: yes
  become_method: super
  become_password: "your_privilege_password"
  # 指定华为VRP系统
  vars:
    ansible_network_os: huawei.huawei_vrp

  tasks:
  - name: 获取设备当前配置
    ansible.netcommon.cli_command:
      command: "display current-configuration"
    register: device_config

  - name: 输出配置结果
    debug:
      var: device_config.stdout_lines

Inventory文件示例(hosts)

如果将配置放在Inventory中,可参考以下格式:

[huawei_node]
huawei_node ansible_host=192.168.1.1 
            ansible_user=your_login_user 
            ansible_password=your_login_password 
            ansible_become=yes 
            ansible_become_method=super 
            ansible_become_password=your_privilege_password 
            ansible_network_os=huawei.huawei_vrp

额外注意事项

  • 提前安装华为Ansible集合:执行ansible-galaxy collection install huawei.huawei_vrp
  • 若设备未配置特权密码(不推荐),可去掉become_password,但仍需保留become: yes和become_method以触发视图切换
  • 测试时可手动登录设备,确认display current-configuration命令在特权视图下可正常执行

内容的提问来源于stack exchange,提问作者Mr A

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.06 15:15:33