Dell C9000 Series Networking Configuration Manual page 974

Hide thumbs Also See for C9000 Series:
Table of Contents

Advertisement

Example: Allow Security Administrator to Access Only 10-Gigabit Ethernet Interfaces
The following example allows the security administrator (secadmin) to only access 10-Gigabit Ethernett
interfaces and then shows that the secadmin, highlighted in bold, can now access Interface mode. However,
the secadmin can only access 10-Gigabit Ethernet interfaces.
Dell(conf)#role configure addrole secadmin ?
LINE
Initial keywords of the command to modify
Dell(conf)#role configure addrole secadmin interface tengigabitethernet
Dell(conf)#show role mode configure interface
Role access: netadmin, secadmin, sysadmin
Example: Verify that the Security Administrator Can Access Interface Mode
The following example shows that the secadmin role can now access Interface mode (highlighted in bold).
Role
Inheritance
netoperator
netadmin
secadmin
sysadmin
Example: Remove Security Administrator Access to Line Mode.
The following example removes the secadmin access to LINE mode and then verifies that the security
administrator can no longer access LINE mode, using the show role mode configure line command in
EXEC Privilege mode.
Dell(conf)#role configure deleterole secadmin ?
LINE
Initial keywords of the command to modify
Dell(conf)#role configure deleterole secadmin line
Dell(conf)#do show role mode ?
configure
exec
interface
line
route-map
router
Dell(conf)#do show role mode configure line
Role access:sysadmin
Example: Grant and Remove Security Administrator Access to Configure Protocols
By default, the system defined role, secadmin, is not allowed to configure protocols. The following example
first grants the secadmin role to configure protocols and then removes access to configure protocols.
Dell(conf)#role configure addrole secadmin protocol
Dell(conf)#role configure deleterole secadmin protocol
Example: Resets Only the Security Administrator role to its original setting.
The following example resets only the secadmin role to its original setting.
Dell(conf)#no role configure addrole secadmin protocol
Example: Reset System-Defined Roles and Roles that Inherit Permissions
Modes
Exec Config Interface Router IP RouteMap Protocol MAC
Exec Config Interface Line
Exec Config Interface Line Router IP RouteMap Protocol MAC
Global configuration mode
Exec Mode
Interface configuration mode
Line Configuration mode
Route map configuration mode
Router configuration mode
Security
974

Advertisement

Table of Contents
loading

Table of Contents