HPE D6020 Maintenance And Service Manual page 39

Hide thumbs Also See for HPE D6020:
Table of Contents

Advertisement

Parameters
security-zone-name&<1-10>: Specifies a space-separated list of up to 10 security zone names.
Each name is a case-sensitive string of 1 to 31 characters.
Usage guidelines
To permit a user role to access a security zone after you configure the security-zone policy deny
command, you must add the security zone to the permitted security zone list of the policy. With the
user role, you can perform the following tasks on the security zones in the permitted security zone
list:
Create, remove, or configure the security zones.
Enter the security zone views.
Specify the security zones in feature commands.
You can repeat the permit security-zone command to add multiple permitted security zones to a
user role security zone policy.
The undo permit security-zone command removes the entire list of permitted security zones if you
do not specify a security zone.
Any change to a user role security zone policy takes effect only on users who log in with the user role
after the change.
Examples
1.
Configure user role role1:
# Permit user role role1 to execute all commands available in system view.
<Sysname> system-view
[Sysname] role name role1
[Sysname-role-role1] rule 1 permit command system-view ; *
# Permit the user role to access security zones trust and abc.
[Sysname-role-role1] security-zone policy deny
[Sysname-role-role1-zonepolicy] permit security-zone trust abc
[Sysname-role-role1-zonepolicy] quit
[Sysname-role-role1] quit
2.
Verify that you cannot use the user role to work on any security zones except for security zones
trust and abc:
# Verify that you can create security zone abc and enter security zone view.
[Sysname] security-zone name abc
[Sysname-security-zone-abc] quit
# Verify that you can create a zone pair with source security zone trust and destination zone
abc.
[Sysname] zone-pair security source trust destination abc
[Sysname-zone-pair-security-Trust-abc] quit
# Verify that you cannot create security zone local or enter the security zone view.
[Sysname] security-zone name local
Permission denied.
Related commands
display role
role
security-zone policy deny
31

Advertisement

Table of Contents
loading

Table of Contents