50
Field Description
Interface policy
Interface policy of the user role:
•
deny
—Denies access to any interface except permitted interfaces.
•
permit (default)
—Default interface policy, which enables the user
role to access any interface.
Permitted interfaces
Interfaces accessible to the user role.
VPN instance policy
VPN instance policy of the user role:
•
deny
—Denies access to any VPN except permitted VPNs.
•
permit (default)
—Default VPN instance policy, which enables the
user role to access any VPN instance.
Permitted VPN instances
VPNs accessible to the user role.
Rule
User role rule number.
A user role rule specifies the access permission for items, including
commands, feature-specific commands, XML elements, and MIB
nodes.
Predefined user role rules are identified by sys-
n
, where
n
represents
an integer.
Perm
Access control criterion:
•
permit
—User role has access to the specified items.
•
deny
—User role does not have access to the specified items.
Type
Item category:
•
R
—Read-only.
•
W
—Write.
•
X
—Execute.
Scope
Rule control scope:
•
command
—Controls access to the command or commands, as
specified in the
Entity
field.
•
feature
—Controls access to the commands of the feature, as
specified in the
Entity
field.
•
feature-group
—Controls access to the commands of the features in
the feature group, as specified in the
Entity
field.
•
xml-element
—Controls access to XML elements.
•
oid
—Controls access to MIB nodes.
Entity
Command string, feature name, feature group, XML element, or OID
specified in the user role rule:
•
An en dash (–) represents any feature.
•
An asterisk (*) represents zero or more characters.
Related commands
role
display role feature
Use
display role feature
to display features available in the system.