HP AE370A Brocade Web Tools Administrator's Guide v6.0.0 (53-1000606-01, April - Page 229

Configuring Standard Security Features, In

Page 229 highlights

Chapter Configuring Standard Security Features 18 In this chapter This chapter contains the following information: •Creating and maintaining user-defined accounts 209 •Configuring access control list policies 217 •Configuring an authentication policy 219 •Configuring SNMP 222 •Managing RADIUS service 224 Creating and maintaining user-defined accounts In addition to the default accounts-root, factory, admin, and user-Fabric OS supports up to 256 user-defined accounts in each logical switch (domain). These accounts expand your ability to track account access and audit administrative activities. Each user-defined account is associated with the following: • Admin Domain list-Specifies what Admin Domains a user account is allowed to log in to. • Home Admin Domain-Specified the Admin Domain that the user is logged in to by default. The home Admin Domain must be a member of the user's Admin Domain list. • Role-Determines functional access levels within the bounds of the user's current Admin Domain. Access rights for any user session are determined both by the user's role-based access rights and by the contents of the currently selected Admin Domain. See Chapter 1, "Introducing Web Tools" for additional information about Admin Domains and Role-Based Access Control (RBAC). The User tab of the Switch Administration window (see Figure 99 on page 211) displays account information. You can create and manage accounts depending on your role: TABLE 14 User role and permissions Role Permissions admin operator securityadmin switchadmin zoneadmin Create and manage all predefined and user-defined accounts Change your own password and cannot create, modify, or view predefined or user-defined accounts Create and manage all security roles. Change your own password and cannot create, modify, or view predefined or user-defined accounts Change your own password and cannot create, modify, or view predefined or user-defined accounts Web Tools Administrator's Guide 209 53-1000606-01

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272

Web Tools Administrator’s Guide
209
53-1000606-01
Chapter
18
Configuring Standard Security Features
In this chapter
This chapter contains the following information:
Creating and maintaining user-defined accounts. . . . . . . . . . . . . . . . . . . . 209
Configuring access control list policies . . . . . . . . . . . . . . . . . . . . . . . . . . . .
217
Configuring an authentication policy . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 219
Configuring SNMP . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 222
Managing RADIUS service . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 224
Creating and maintaining user-defined accounts
In addition to the default accounts—root, factory, admin, and user—Fabric OS supports up to 256
user-defined accounts in each logical switch (domain). These accounts expand your ability to track
account access and audit administrative activities.
Each user-defined account is associated with the following:
Admin Domain list—Specifies what Admin Domains a user account is allowed to log in to.
Home Admin Domain—Specified the Admin Domain that the user is logged in to by default. The
home Admin Domain must be a member of the user’s Admin Domain list.
Role—Determines functional access levels within the bounds of the user’s current Admin
Domain.
Access rights for any user session are determined both by the user’s role-based access rights and
by the contents of the currently selected Admin Domain. See
Chapter 1, “Introducing Web Tools”
for
additional information about Admin Domains and Role-Based Access Control (RBAC).
The
User
tab of the Switch Administration window (see
Figure 99
on page 211) displays account
information. You can create and manage accounts depending on your role:
TABLE 14
User role and permissions
Role
Permissions
admin
Create and manage all predefined and user-defined accounts
operator
Change your own password and cannot create, modify, or view predefined or
user-defined accounts
securityadmin
Create and manage all security roles.
switchadmin
Change your own password and cannot create, modify, or view predefined or
user-defined accounts
zoneadmin
Change your own password and cannot create, modify, or view predefined or
user-defined accounts