Assigning User Roles; Assigning User Roles To Remote Aaa Authentication Users; Assigning User Roles To Local Aaa Authentication Users - HP 12500 Configuration Manual

Routing switch series
Table of Contents

Advertisement

Step
3.
Enter user role VPN
instance policy view.
4.
(Optional.) Specify a list of
VPNs accessible to the user
role.

Assigning user roles

To control user access to the system, you must assign at least one user role. Make sure at least one user
role among the user roles assigned by the server exists on the device. User role assignment procedure
varies with remote AAA authentication users, local AAA authentication users, and non-AAA
authentication users (see

Assigning user roles to remote AAA authentication users

A remote AAA authentication user must have at least one user role to log in to the device.
User roles are configured on the RADIUS server. For information about configuring user roles for a
RADIUS user, see the RADIUS server documentation.
You can configure the default user role function to enable a remote AAA authentication user that has not
been assigned any user role to log in with a default user role.
For login to the default MDC, the default user role is network-operator.
For login to a non-default MDC, the default user role is mdc-operator.
For more information about AAA authentication, see Security Configuration Guide.
To enable the default user role function for remote AAA authentication users:
Step
1.
Enter system view.
2.
Enable the default user role
function.

Assigning user roles to local AAA authentication users

Configure user roles for local AAA authentication users in their local user accounts. Every local user has
a default user role. If this default user role is not suitable, delete it. Because a local user must have at least
one user role, the last user role cannot be deleted.
To assign a user role to a local user:
Step
1.
Enter system view.
Command
vpn-instance policy deny
permit vpn-instance
vpn-instance-name&<1-10>
"Assigning user
roles").
Command
system-view
role default-role enable
Command
system-view
21
Remarks
By default, the VPN policies of user
roles permit access to all VPNs.
This command disables the access of
the user role to any VPN.
By default, no accessible VPNs are
configured.
To add more accessible VPNs, repeat
this step.
Remarks
N/A
The default user role function is
disabled.
Remarks
N/A

Advertisement

Table of Contents
loading

Table of Contents