HP 6125XLG R2306-HP 6125XLG Blade Switch Fundamentals Configuration Guide - Page 53

Configuring user role rules, Configuring feature groups

Page 53 highlights

Configuring user role rules Configure command, feature, and feature group rules to permit or deny the access of a user role to specific commands. You can configure up to 256 rules for a user role, but the total number of user role rules in the system cannot exceed 1024. If two rules of a user role conflict, the one with a higher rule number has priority. Any rule modification, addition, or removal for a user role takes effect only on users that are logged in with the user role after the change. To configure rules for a user role: Step 1. Enter system view. 2. Enter user role view. Command system-view role name role-name 3. Configure a rule. • Configure a command rule: rule number { deny | permit } command command-string • Configure a feature rule: rule number { deny | permit } { execute | read | write } * feature [ feature-name ] • Configure a feature group rule: rule number { deny | permit } { execute | read | write } * feature-group feature-group-name Remarks N/A N/A Configure at least one command. By default, a user-defined user role has no rules or access to any command. Repeat this step to add up to 256 rules to the user role. IMPORTANT: When you configure feature rules, you can specify only features available in the system and must enter feature names exactly the same as they are displayed, including the case. Configuring feature groups Use feature groups to bulk assign command access permissions to sets of features. In addition to the predefined feature groups, you can create up to 64 custom feature groups and assign a feature to multiple feature groups. To configure a feature group: Step 1. Enter system view. Command system-view Remarks N/A 46

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155

46
Configuring user role rules
Configure command, feature, and feature group rules to permit or deny the access of a user role to
specific commands.
You can configure up to 256 rules for a user role, but the total number of user role rules in the system
cannot exceed 1024.
If two rules of a user role conflict, the one with a higher rule number has priority.
Any rule modification, addition, or removal for a user role takes effect only on users that are logged in
with the user role after the change.
To configure rules for a user role:
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter user role view.
role name
role-name
N/A
3.
Configure a rule.
Configure a command rule:
rule
number
{
deny
|
permit
}
command
command-string
Configure a feature rule:
rule
number
{
deny
|
permit
}
{
execute
|
read
|
write
} *
feature
[
feature-name
]
Configure a feature group rule:
rule
number
{
deny
|
permit
}
{
execute
|
read
|
write
} *
feature-group
feature-group-name
Configure at least one command.
By default, a user-defined user role
has no rules or access to any
command.
Repeat this step to add up to 256
rules to the user role.
IMPORTANT:
When you configure feature rules,
you can specify only features
available in the system and must
enter feature names exactly the same
as they are displayed, including the
case.
Configuring feature groups
Use feature groups to bulk assign command access permissions to sets of features. In addition to the
predefined feature groups, you can create up to 64 custom feature groups and assign a feature to
multiple feature groups.
To configure a feature group:
Step
Command
Remarks
1.
Enter system view.
system-view
N/A