19
[Sysname-role-role1] rule 1 permit command system-view ; *
# Permit the user role to access VPN instance
vpn1
.
[Sysname-role-role1] vpn policy deny
[Sysname-role-role1-vpnpolicy] permit vpn-instance vpn1
[Sysname-role-role1-vpnpolicy] quit
[Sysname-role-role1] quit
2.
Verify that you cannot use user role
role1
to work on any VPN instances except for
vpn1
:
# Verify that you can enter the view of
vpn1
.
[Sysname] ip vpn-instance vpn1
[Sysname-vpn-instance-vpn1] quit
# Verify that you can specify the primary accounting server at 10.110.1.2 in VPN instance
vpn1
for RADIUS scheme
radius1
.
[Sysname] radius scheme radius1
[Sysname-radius-radius1] primary accounting 10.110.1.2 vpn-instance vpn1
[Sysname-radius-radius1] quit
# Verify that you cannot create VPN instance
vpn2
or enter VPN instance view.
[Sysname] ip vpn-instance vpn2
Permission denied.
Related commands
display role
role
vpn-instance policy deny
role
Use
role
to create a user role and enter its view, or enter the view of an existing user role.
Use
undo role
to delete a user role.
Syntax
role name
role-name
undo role name role-name
Default
The system has the following predefined user roles: network-admin, network-operator, level-
n
(where
n
represents an integer in the range of 0 to 15), and security-audit.
Views
System view
Predefined user roles
network-admin
Parameters
name role-name
: Specifies a username. The
role-name
argument is a case-sensitive string of
1 to 63 characters.
Usage guidelines
You can create a maximum of 64 user roles in addition to the predefined user roles.
Summary of Contents for SOHO IE4300
Page 285: ...i Contents Tcl commands 1 cli 1 tclquit 1 tclsh 2...
Page 288: ...i Contents Python commands 1 exit 1 python 1 python filename 2...
Page 291: ...i Contents Automatic configuration commands 1 autodeploy udisk enable 1...
Page 323: ...25 Sysname Ten GigabitEthernet1 0 51 undo shutdown Related commands irf port...
Page 465: ...ii stp vlan enable 55 vlan mapping modulo 55...
Page 602: ...12 Related commands display mvrp statistics...
Page 609: ...i Contents VLAN mapping commands 1 display vlan mapping 1 vlan mapping 2...
Page 678: ...9 Related commands reset pppoe relay statistics...
Page 846: ...i Contents Basic IP forwarding commands 1 display fib 1 ip forwarding table save 2...
Page 1770: ...i Contents Time range commands 1 display time range 1 time range 1...
Page 2026: ...34 Related commands display mac authentication...
Page 2028: ...ii...
Page 2143: ...i Contents User profile commands 1 display user profile 1 user profile 2...
Page 2308: ...61 ipsec transform set...
Page 2531: ...i Contents SAVI commands 1 ipv6 savi down delay 1 ipv6 savi log enable 1 ipv6 savi strict 2...
Page 2534: ...3 Sysname ipv6 savi strict Related commands ipv6 verify source...
Page 2791: ...14 Sysname track 1 Related commands delay display track...
Page 2939: ...9 sntp authentication keyid sntp reliable authentication keyid...
Page 2967: ...27 Related commands apply poe profile poe enable poe max power interface view poe priority...