HP 6125XLG R2306-HP 6125XLG Blade Switch Fundamentals Command Reference - Page 71

vpn-instance policy deny

Page 71 highlights

vpn-instance policy deny Use vpn-instance policy deny to enter user role VPN instance policy view. Use undo vpn-instance policy deny to restore the default user role VPN instance policy. Syntax vpn-instance policy deny undo vpn-instance policy deny Default A user role has access to any VPN. Views User role view Predefined user roles network-admin Usage guidelines The vpn-instance policy deny command denies the access of a user role to any VPN. To restrict the VPN access of a user role to only a set of VPNs: 1. Use vpn-instance policy deny to deny access to any VPN. 2. Use permit vpn-instance to specify accessible VPNs. To perform any of the following operations, you must make sure the VPN is permitted by the VPN instance policy of any user role that you are logged in with: • Create, remove, or configure an MPLS L3VPN. • Enter its view. • Specify it in a feature command, Any change to a user role VPN instance policy takes effect only on users that log in with the user role after the change. Examples # Deny the access of user role role1 to any VPN. system-view [Sysname] role name role1 [Sysname-role-role1] vpn-instance policy deny [Sysname-role-role1-vpnpolicy] quit # Deny the access of user role role1 to any VPN but vpn2. system-view [Sysname] role name role1 [Sysname-role-role1] vpn-instance policy deny [Sysname-role-role1-vpnpolicy] permit vpn-instance vpn2 Related commands • display role • permit vpn-instance • role 64

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221

64
vpn-instance policy deny
Use
vpn-instance policy deny
to enter user role VPN instance policy view.
Use
undo vpn-instance policy deny
to restore the default user role VPN instance policy.
Syntax
vpn-instance policy deny
undo vpn-instance policy deny
Default
A user role has access to any VPN.
Views
User role view
Predefined user roles
network-admin
Usage guidelines
The
vpn-instance policy deny
command denies the access of a user role to any VPN.
To restrict the VPN access of a user role to only a set of VPNs:
1.
Use
vpn-instance policy deny
to deny access to any VPN.
2.
Use
permit vpn-instance
to specify accessible VPNs.
To perform any of the following operations, you must make sure the VPN is permitted by the VPN
instance policy of any user role that you are logged in with:
Create, remove, or configure an MPLS L3VPN.
Enter its view.
Specify it in a feature command,
Any change to a user role VPN instance policy takes effect only on users that log in with the user role after
the change.
Examples
# Deny the access of user role
role1
to any VPN.
<Sysname> system-view
[Sysname] role name role1
[Sysname-role-role1] vpn-instance policy deny
[Sysname-role-role1-vpnpolicy] quit
# Deny the access of user role
role1
to any VPN but
vpn2
.
<Sysname> system-view
[Sysname] role name role1
[Sysname-role-role1] vpn-instance policy deny
[Sysname-role-role1-vpnpolicy] permit vpn-instance vpn2
Related commands
display role
permit vpn-instance
role