HP 6125XLG R2306-HP 6125XLG Blade Switch Fundamentals Command Reference - Page 48

Predefined user roles, Parameters, Usage guidelines, Examples, Field, Description

Page 48 highlights

Predefined user roles network-admin network-operator Parameters name role-name: Specifies a user role name, a case-sensitive string of 1 to 63 characters. Usage guidelines If no user role name is specified, the command displays information about all user roles, including the predefined user roles. Examples # Display information about the user role 123. display role name 123 Role: 123 Description: new role VLAN policy: deny Permitted VLANs: 1 to 5, 7 to 8 Interface policy: deny Permitted interfaces: Ten-GigabitEthernet1/1/5 to Ten-GigabitEthernet1/1/7, Vlan-interface1 to Vlan-interface20 VPN instance policy: deny Permitted VPN instances: vpn, vpn1, vpn2 Rule Perm Type Scope Entity 1 permit RWX feature-group abc 2 deny -W- feature ldap 3 permit command system ; radius sc * R:Read W:Write X:Execute Table 4 Command output Field Role Description VLAN policy Permitted VLANs Interface policy Description User role name. Predefined user role names include network-admin, network-operator, level-n (where n represents an integer in the range of 0 to 15), and security-audit. User role description you have configured for easy identification. VLAN policy of the user role: • deny-Denies access to any VLAN except permitted VLANs. • permit (default)-Default VLAN policy, which enables the user role to access any VLAN. VLANs accessible to the user role. Interface policy of the user role: • deny-Denies access to any interface except permitted interfaces. • permit (default)-Default interface policy, which enables the user role to access any interface. 41

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221

41
Predefined user roles
network-admin
network-operator
Parameters
name
role-name
: Specifies a user role name, a case-sensitive string of 1 to 63 characters.
Usage guidelines
If no user role name is specified, the command displays information about all user roles, including the
predefined user roles.
Examples
# Display information about the user role
123
.
<Sysname> display role name 123
Role: 123
Description: new role
VLAN policy: deny
Permitted VLANs: 1 to 5, 7 to 8
Interface policy: deny
Permitted interfaces: Ten-GigabitEthernet1/1/5 to Ten-GigabitEthernet1/1/7,
Vlan-interface1 to Vlan-interface20
VPN instance policy: deny
Permitted VPN instances: vpn, vpn1, vpn2
-------------------------------------------------------------------
Rule
Perm
Type
Scope
Entity
-------------------------------------------------------------------
1
permit RWX
feature-group abc
2
deny
-W-
feature
ldap
3
permit
command
system ; radius sc *
R:Read W:Write X:Execute
Table 4
Command output
Field
Description
Role
User role name.
Predefined user role names include network-admin, network-operator,
level-
n
(where n represents an integer in the range of 0 to 15), and
security-audit.
Description
User role description you have configured for easy identification.
VLAN policy
VLAN policy of the user role:
deny
—Denies access to any VLAN except permitted VLANs.
permit (default)
—Default VLAN policy, which enables the user role
to access any VLAN.
Permitted VLANs
VLANs accessible to the user role.
Interface policy
Interface policy of the user role:
deny
—Denies access to any interface except permitted interfaces.
permit (default)
—Default interface policy, which enables the user
role to access any interface.