HP 6125XLG R2306-HP 6125XLG Blade Switch Fundamentals Command Reference - Page 70

vlan policy deny

Page 70 highlights

vlan policy deny Use vlan policy deny to enter the user role VLAN policy view. Use undo vlan policy deny to restore the default user role VLAN policy. Syntax vlan policy deny undo vlan policy deny Default A user role has no access to any VLAN. Views User role view Predefined user roles network-admin Usage guidelines The vlan policy deny command denies the access of a user role to any VLAN. To restrict the VLAN access of a user role to only a set of VLANs: 1. Use vlan policy deny to deny access to any VLAN. 2. Use permit vlan to specify accessible VLANs. To perform any of the following operations, you must make sure the VLAN is permitted by the VLAN policy of any user role that you are logged in with: • Create, remove, or configure a VLAN. • Enter its view. • Specify the VLAN in a feature command. Any change to a user role VLAN policy takes effect only on users that log in with the user role after the change. Examples # Deny the access of role1 to any VLAN. system-view [Sysname] role name role1 [Sysname-role-role1] vlan policy deny [Sysname-role-role1-vlanpolicy] quit # Deny the access of role1 to any VLAN but VLANs 50 to 100. system-view [Sysname] role name role1 [Sysname-role-role1] vlan policy deny [Sysname-role-role1-vlanpolicy] permit vlan 50 to 100 Related commands • display role • permit vlan • role 63

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221

63
vlan policy deny
Use
vlan policy deny
to enter the user role VLAN policy view.
Use
undo vlan policy deny
to restore the default user role VLAN policy.
Syntax
vlan policy deny
undo vlan policy deny
Default
A user role has no access to any VLAN.
Views
User role view
Predefined user roles
network-admin
Usage guidelines
The
vlan policy deny
command denies the access of a user role to any VLAN.
To restrict the VLAN access of a user role to only a set of VLANs:
1.
Use
vlan policy deny
to deny access to any VLAN.
2.
Use
permit vlan
to specify accessible VLANs.
To perform any of the following operations, you must make sure the VLAN is permitted by the VLAN
policy of any user role that you are logged in with:
Create, remove, or configure a VLAN.
Enter its view.
Specify the VLAN in a feature command.
Any change to a user role VLAN policy takes effect only on users that log in with the user role after the
change.
Examples
# Deny the access of
role1
to any VLAN.
<Sysname> system-view
[Sysname] role name role1
[Sysname-role-role1] vlan policy deny
[Sysname-role-role1-vlanpolicy] quit
# Deny the access of
role1
to any VLAN but VLANs 50 to 100.
<Sysname> system-view
[Sysname] role name role1
[Sysname-role-role1] vlan policy deny
[Sysname-role-role1-vlanpolicy] permit vlan 50 to 100
Related commands
display role
permit vlan
role