•
System Administrator—Can perform all system-wide activities, Domain Administrator
activities, and IDP Administrator activities.
•
Read-Only System Administrator—Can perform all read-only system-wide activities
and Domain Administrator activities.
Each default role contains activities that relate to the traditional responsibilities for a
specific job title. Use a default role to create quickly an NSM administrator or to create
administrators when your organization’s existing permission structure maps closely to
the permissions defined in the default role.
All roles, default and custom, are created from activities. In a default role, the activities
are chosen for you; in a custom role, you choose the activities that make up the desired
functionality. See “Creating Custom Roles” on page 75 for details.
NOTE:
Role assignment is additive. When you assign multiple roles to a single
administrator, the permissions specified by the activities in the role are added.
You must also select a domain. You can assign administrators to the global domain, or
to one or more subdomains (the subdomain must already exist). Administrators must
log in to the domain they were created in. For example, the super administrator has access
to all domains, but must log in to the global domain first, and then switch to a subdomain
using the domain menu. For details on creating a subdomain, see “Creating Subdomains”
on page 91.
Creating Custom Roles
For more complex and diverse permissions requirements, create custom roles to specify
the exact level of permission you want to give an administrator. An
activity
is a predefined
task that defines access to a function in NSM. To assign one or more activities to an NSM
administrator, create a role that includes those activities and assign the role to the
administrator.
Some activities are dependant on other activities. If you select a dependant activity, NSM
automatically selects the prerequisite activities. You can clear prerequisite activities from
a custom role, but doing so affects permissions granted in the dependant activity. For
example, if you create a role that includes the activity “Create VPNs”, the activities “Edit
VPNs” and “View VPNs” are automatically selected for you.
Click the Add icon to display the New Role dialog box and all available activities. NSM
includes many predefined activities, grouped by similar functionality. See Table 16 on
page 75.
Table 16: Predefined NSM Administrator Activities
Description
Task
Function
The Action Manager is a node on the main navigation tree that enables
you to configure the management system to forward logs generated
within a specific domain or subdomain.
View
Modify
Action Attributes
75
Copyright © 2010, Juniper Networks, Inc.
Chapter 3: Configuring Role-Based Administration
Содержание NETWORK AND SECURITY MANAGER 2010.4 - ADMININISTRATION GUIDE REV1
Страница 6: ...Copyright 2010 Juniper Networks Inc vi...
Страница 36: ...Copyright 2010 Juniper Networks Inc xxxvi Network and Security Manager Administration Guide...
Страница 52: ...Copyright 2010 Juniper Networks Inc 2 Network and Security Manager Administration Guide...
Страница 90: ...Copyright 2010 Juniper Networks Inc 40 Network and Security Manager Administration Guide...
Страница 146: ...Copyright 2010 Juniper Networks Inc 96 Network and Security Manager Administration Guide...
Страница 236: ...Copyright 2010 Juniper Networks Inc 186 Network and Security Manager Administration Guide...
Страница 292: ...Copyright 2010 Juniper Networks Inc 242 Network and Security Manager Administration Guide...
Страница 314: ...Copyright 2010 Juniper Networks Inc 264 Network and Security Manager Administration Guide...
Страница 368: ...Copyright 2010 Juniper Networks Inc 318 Network and Security Manager Administration Guide...
Страница 370: ...Copyright 2010 Juniper Networks Inc 320 Network and Security Manager Administration Guide...
Страница 484: ...Copyright 2010 Juniper Networks Inc 434 Network and Security Manager Administration Guide...
Страница 584: ...Copyright 2010 Juniper Networks Inc 534 Network and Security Manager Administration Guide...
Страница 588: ...Copyright 2010 Juniper Networks Inc 538 Network and Security Manager Administration Guide...
Страница 600: ...Copyright 2010 Juniper Networks Inc 550 Network and Security Manager Administration Guide...
Страница 678: ...Copyright 2010 Juniper Networks Inc 628 Network and Security Manager Administration Guide...
Страница 694: ...Copyright 2010 Juniper Networks Inc 644 Network and Security Manager Administration Guide...
Страница 700: ...Copyright 2010 Juniper Networks Inc 650 Network and Security Manager Administration Guide...
Страница 706: ...Copyright 2010 Juniper Networks Inc 656 Network and Security Manager Administration Guide...
Страница 708: ...Copyright 2010 Juniper Networks Inc 658 Network and Security Manager Administration Guide...
Страница 758: ...Copyright 2010 Juniper Networks Inc 708 Network and Security Manager Administration Guide...
Страница 788: ...Copyright 2010 Juniper Networks Inc 738 Network and Security Manager Administration Guide...
Страница 882: ...Copyright 2010 Juniper Networks Inc 832 Network and Security Manager Administration Guide...
Страница 908: ...Copyright 2010 Juniper Networks Inc 858 Network and Security Manager Administration Guide...
Страница 918: ...Copyright 2010 Juniper Networks Inc 868 Network and Security Manager Administration Guide...
Страница 920: ...Copyright 2010 Juniper Networks Inc 870 Network and Security Manager Administration Guide...
Страница 1005: ...PART 6 Index Index on page 957 955 Copyright 2010 Juniper Networks Inc...
Страница 1006: ...Copyright 2010 Juniper Networks Inc 956 Network and Security Manager Administration Guide...