HP 6125XLG R2306-HP 6125XLG Blade Switch Fundamentals Configuration Guide - Page 54

Changing resource access policies, Changing the interface policy of a user role

Page 54 highlights

Step Command 2. Create a feature group and enter feature group role feature-group name view. feature-group-name 3. Add a feature to the feature group. feature feature-name Remarks By default, the system has the following predefined feature groups: • L2-Includes all Layer 2 commands. • L3-Includes all Layer 3 commands. These two groups are not user configurable. By default, a feature group has no features. IMPORTANT: You can specify only features available in the system and must enter feature names exactly the same as they are displayed, including the case. Changing resource access policies Every user role has one interface policy, VLAN policy, and VPN instance policy. By default, these policies permit user roles to access any interface, VLAN, and VPN. You can change the policies of user-defined user roles and the predefined level-n user roles to limit their access to interfaces, VLANs, and VPNs. A changed policy takes effect only on users that are logged in with the user role after the change. Changing the interface policy of a user role Step 1. Enter system view. 2. Enter user role view. Command system-view role name role-name 3. Enter user role interface policy view. interface policy deny 4. (Optional.) Specify a list of interfaces accessible to the permit interface interface-list user role. Remarks N/A N/A By default, the interface policies of user roles permit access to all interfaces. This command disables the access of the user role to any interface. By default, no accessible interfaces are configured. To add more accessible interfaces, repeat this step. 47

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155

47
Step
Command
Remarks
2.
Create a feature group
and enter feature group
view.
role feature-group name
feature-group-name
By default, the system has the
following predefined feature
groups:
L2
—Includes all Layer 2
commands.
L3
—Includes all Layer 3
commands.
These two groups are not user
configurable.
3.
Add a feature to the
feature group.
feature
feature-name
By default, a feature group has no
features.
IMPORTANT:
You can specify only features
available in the system and must
enter feature names exactly the
same as they are displayed,
including the case.
Changing resource access policies
Every user role has one interface policy, VLAN policy, and VPN instance policy. By default, these policies
permit user roles to access any interface, VLAN, and VPN. You can change the policies of user-defined
user roles and the predefined level-n user roles to limit their access to interfaces, VLANs, and VPNs. A
changed policy takes effect only on users that are logged in with the user role after the change.
Changing the interface policy of a user role
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter user role view.
role name
role-name
N/A
3.
Enter user role interface
policy view.
interface policy deny
By default, the interface policies of
user roles permit access to all
interfaces.
This command disables the access of
the user role to any interface.
4.
(Optional.) Specify a list of
interfaces accessible to the
user role.
permit interface
interface-list
By default, no accessible interfaces
are configured.
To add more accessible interfaces,
repeat this step.