
S e n d f e e d b a c k t o n x 5 0 0 0 - d o c f e e d b a c k @ c i s c o . c o m
1-7
Cisco Nexus 5000 Series Switch CLI Software Configuration Guide
OL-16597-01
Chapter 1 Configuring User Accounts and RBAC
Configuring RBAC
Creating Feature Groups
To create feature groups, perform this task:
Changing User Role Interface Policies
You can change a user role interface policy to limit the interfaces that the user can access. To change a
user role interface policy, perform this task:
Command
Purpose
Step 1
switch#
configure terminal
Enters global configuration mode.
Step 2
switch(config)#
role feature-group
group-name
Specifies a user role feature group and enters role
feature group configuration mode.
The
group-name
argument is a case-sensitive,
alphanumeric character string with a maximum
length of 32 characters.
Step 3
switch(config-role-featuregrp)#
exit
Exits role feature group configuration mode.
Step 4
switch(config)#
show role feature-group
(Optional) Displays the role feature group
configuration.
Step 5
switch(config)#
copy running-config
startup-config
(Optional) Copies the running configuration to the
startup configuration.
Command
Purpose
Step 1
switch#
configure terminal
Enters global configuration mode.
Step 2
switch(config)#
role name
role-name
Specifies a user role and enters role configuration
mode.
Step 3
switch(config-role)#
rule
number
permit
command
configure terminal ; interface *
Configures a command rule to allow access to all
interfaces.
Step 4
switch(config-role)#
interface policy deny
Enters role interface policy configuration mode.
Step 5
switch(config-role-interface)#
permit
interface
interface-list
Specifies a list of interfaces that the role can access.
Repeat this command for as many interfaces as
needed.
For this command, you can specify Ethernet
interfaces, Fibre Channel interfaces and virtual
Fibre Channel interfaces.
Step 6
switch(config-role-interface)#
exit
Exits role interface policy configuration mode.