24
Configuring resource access policies
Every user role has one interface policy, VLAN policy, and VPN instance policy. By default, these
policies permit a user role to access any interface, VLAN, and VPN instance. You can configure the
policies of a user-defined user role or a predefined level-
n
user role to limit its access to interfaces,
VLANs, and VPN instances. The policy configuration takes effect only on users that are logged in
with the user role after the configuration.
Configuring the user role interface policy
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter user role view.
role name role-name
N/A
3.
Enter user role interface
policy view.
interface policy deny
By default, the interface policy of the
user role permits access to all
interfaces.
This command denies the access of
the user role to all interfaces if the
permit interface
command is not
configured.
4.
(Optional.) Specify a list of
interfaces accessible to
the user role.
permit interface interface-list
By default, no accessible interfaces
are configured in user role interface
policy view.
Repeat this step to add multiple
accessible interfaces.
Configuring the user role VLAN policy
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter user role view.
role name role-name
N/A
3.
Enter user role VLAN
policy view.
vlan policy deny
By default, the VLAN policy of the
user role permits access to all
VLANs.
This command denies the access of
the user role to all VLANs if the
permit vlan
command is not
configured.
4.
(Optional.) Specify a list of
VLANs accessible to the
user role.
permit vlan vlan-id-list
By default, no accessible VLANs are
configured in user role VLAN policy
view.
Repeat this step to add multiple
accessible VLANs.
Содержание FlexNetwork 10500 Series
Страница 139: ...130 Sysname display version ...