21
The service type of an administrator can be SSH, Telnet, FTP, HTTP, HTTPS, PAD, or terminal. A
terminal user can access the device through the console, Aux, or Async port.
User account management
A user account on the device manages attributes for users who log in to the device with the same
username. The attributes include the username, password, services, and password control
parameters.
Role-based access control
Assign users user roles to control the users' access to functions and system resources. Assigning
permissions to a user role includes the following:
•
Defines a set of rules to determine accessible or inaccessible functions for the user role.
•
Configures resource access policies to specify which interfaces and VLANs are accessible to
the user role.
To configure a function related to a resource (an interface or VLAN), a user role must have access to
both the function and the resource.
Resource access policies
Resource access policies control access of user roles to system resources and include the following
types:
•
Interface
policy
—Controls access to interfaces.
•
VLAN
policy
—Controls access to VLANs.
You can perform the following tasks on an accessible interface, VLAN:
•
Create or remove the interface or VLAN.
•
Configure attributes for the interface or VLAN.
•
Apply the interface or VLAN to other parameters.
Predefined user roles
The system provides predefined user roles. These user roles have access to all system resources
(interfaces and VLANs). Their access permissions differ.
If the predefined user roles cannot meet the access requirements, you can define new user roles to
control the access permissions for users.
IMPORTANT:
The security-audit user role has access only to security log menus. Security log menus are not
supported on the current Web interface, so do not assign the security-audit user role to any users.
Assigning user roles
Depending on the authentication method, user role assignment has the following methods:
•
Local
authorization
—If the user passes local authorization, the device assigns the user roles
specified in the local user account.
•
Remote
authorization
—If the user passes remote authorization, the remote AAA server
assigns the user roles specified on the server.
A user who fails to obtain a user role is logged out of the device.
If multiple user roles are assigned to a user, the user can use the collection of functions and
resources accessible to all the user roles.