User and Group Management
Best User and Group Management Practices
When adding additional users and groups to your configuration, follow these guidelines to
establish object permissions that will be effective and easy to manage:
If you require multiple non-admin users in your configuration, it is preferable to first create all
required objects (servers, server pools, clusters, etc.), and then create users with appropriate
permissions to manage them.
In the easiest to manage scenario:
l
There is one user with the "admin" flag set.
l
The "admin" user creates all objects.
l
The "admin" user assigns users "read", "write", and "delete" permissions on objects in the
configuration (as necessary) so that those users can perform required tasks on those
objects (see Table).
l
A user can be given permission to perform certain administrative tasks by enabling the
"read_global" and "write_global" flags for that user (See
l
No groups other than "Default" are used.
The next step up in complexity is to give a non-admin user the ability to create objects of a
particular type.
An even more advanced mode allows users to create objects of a certain type and add them to a
group other than "Default" as well. In this scenario, an "admin" user must update the users
"permit" list to give the non-admin user access to any new objects the non-admin user creates.
In general, it is recommended that the "admin" flag and the "create" permission are enabled for
as few users as possible. Otherwise, chaos may ensue. You have been warned!
Note
- By default Equalizer comes with an admin user “touch”. User permissions can only be assigned by an admin-
istrator using the eqcli command line interface.
734
Copyright © 2014 Coyote Point Systems, A Subsidiary of Fortinet, Inc.
Содержание Equalizer GX Series
Страница 18: ......
Страница 32: ...Overview 32 Copyright 2014 Coyote Point Systems A Subsidiary of Fortinet Inc ...
Страница 42: ......
Страница 52: ......
Страница 64: ......
Страница 72: ......
Страница 76: ......
Страница 123: ...Copyright 2014 Coyote Point Systems A Subsidiary of Fortinet Inc All Rights Reserved 123 Equalizer Administration Guide ...
Страница 228: ......
Страница 238: ......
Страница 411: ...Copyright 2014 Coyote Point Systems A Subsidiary of Fortinet Inc All Rights Reserved 411 Equalizer Administration Guide ...
Страница 459: ...Copyright 2014 Coyote Point Systems A Subsidiary of Fortinet Inc All Rights Reserved 459 Equalizer Administration Guide ...
Страница 476: ......
Страница 492: ......
Страница 530: ......
Страница 614: ......
Страница 626: ......
Страница 638: ......
Страница 678: ......
Страница 732: ...Using SNMP Traps 732 Copyright 2014 Coyote Point Systems A Subsidiary of Fortinet Inc ...
Страница 754: ......
Страница 790: ......
Страница 804: ......
Страница 842: ......
Страница 847: ...Copyright 2014 Coyote Point Systems A Subsidiary of Fortinet Inc All Rights Reserved 847 Equalizer Administration Guide ...
Страница 866: ......