S e n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a c k - d o c @ c i s c o . c o m
39-7
Cisco MDS 9000 Family CLI Configuration Guide
OL-16184-01, Cisco MDS SAN-OS Release 3.x
Chapter 39 Configuring Users and Common Roles
Role Distributions
Example 39-1 Displays Information for All Roles
switch#
show role
Role: network-admin
Description: Predefined Network Admin group. This role cannot be modified
Access to all the switch commands
Role: network-operator
Description: Predefined Network Operator group. This role cannot be modified
Access to Show commands and selected Exec commands
Role: svc-admin
Description: Predefined SVC Admin group. This role cannot be modified
Access to all SAN Volume Controller commands
Role: svc-operator
Description: Predefined SVC Operator group. This role cannot be modified
Access to selected SAN Volume Controller commands
Role: TechDocs
vsan policy: permit (default)
Role: sangroup
Description: SAN management group
vsan policy: deny
Permitted vsans: 10-30
---------------------------------------------
Rule Type Command-type Feature
---------------------------------------------
1. permit config *
2. deny config fspf
3. permit debug zone
4. permit exec fcping
Displaying Roles When Distribution is Enabled
Use the
show role
command to display the configuration database.
Use the
show role status
command to display whether distribution is enabled for role configuration, the
current fabric status (locked or unlocked), and the last operation performed. See
Example 39-2
.
Example 39-2 Displays the Role Status Information
switch#
show role
status
Distribution: Enabled
Session State: Locked
Last operation (initiated from this switch): Distribution enable
Last operation status: Success
Use the
show role pending
command to display the pending role database.
Example 39-3
displays the output of the
show role pending
command by following this procedure:
1.
Create the role called
myrole
using the
role name myrole
command.
2.
Issue the
rule 1 permit config feature fspf
command.
3.
Issue the
show role pending
command to see the output.