HP 6125XLG R2306-HP 6125XLG Blade Switch Fundamentals Command Reference - Page 56

interface policy deny, Related commands, Syntax, Default, Views, Predefined user roles

Page 56 highlights

Related commands • display role feature • display role feature-group • role feature-group interface policy deny Use interface policy deny to enter user role interface policy view. Use undo interface policy deny to restore the default user role interface policy. Syntax interface policy deny undo interface policy deny Default A user role has access to any interface. Views User role view Predefined user roles network-admin Usage guidelines The interface policy deny command denies the access of a user role to any interface. To restrict the interface access of a user role to only a set of interfaces: 1. Use interface policy deny to deny access to any interface. 2. Use permit interface to specify accessible interfaces. To perform any of the following operations, you must make sure the interface is permitted by the interface policy of any user role that you are logged in with: • Create, remove, or configure an interface. • Enter its interface view. • Specify the interface in a feature command. The create and remove operations are available only to logical interfaces. Any change to a user role interface policy takes effect only on users who log in with the user role after the change. Examples # Deny the user role role1 to access any interface. system-view [Sysname] role name role1 [Sysname-role-role1] interface policy deny [Sysname-role-role1-ifpolicy] quit # Deny the user role role1 to access any interface but Ten-GigabitEthernet 1/1/5 to Ten-GigabitEthernet 1/1/9. system-view 49

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221

49
Related commands
display role feature
display role feature-group
role feature-group
interface policy deny
Use
interface policy deny
to enter user role interface policy view.
Use
undo interface policy deny
to restore the default user role interface policy.
Syntax
interface policy deny
undo interface policy deny
Default
A user role has access to any interface.
Views
User role view
Predefined user roles
network-admin
Usage guidelines
The
interface policy deny
command denies the access of a user role to any interface.
To restrict the interface access of a user role to only a set of interfaces:
1.
Use
interface policy deny
to deny access to any interface.
2.
Use
permit interface
to specify accessible interfaces.
To perform any of the following operations, you must make sure the interface is permitted by the interface
policy of any user role that you are logged in with:
Create, remove, or configure an interface.
Enter its interface view.
Specify the interface in a feature command.
The create and remove operations are available only to logical interfaces.
Any change to a user role interface policy takes effect only on users who log in with the user role after the
change.
Examples
# Deny the user role
role1
to access any interface.
<Sysname> system-view
[Sysname] role name role1
[Sysname-role-role1] interface policy deny
[Sysname-role-role1-ifpolicy] quit
# Deny the user role
role1
to access any interface but Ten-GigabitEthernet 1/1/5 to Ten-GigabitEthernet
1/1/9.
<Sysname> system-view