Permit Vlan - HP MSR Series Command Reference Manual

Hide thumbs Also See for MSR Series:
Table of Contents

Advertisement

# Verify that you can enter GigabitEthernet 2/1/0 interface view.
<Sysname> system-view
[Sysname] interface gigabitethernet 2/1/0
[Sysname-GigabitEthernet2/1/0]
# Verify that you can assign GigabitEthernet 2/1/4 to VLAN 10. In this example, the user role can
access any VLAN because the default VLAN policy of the user role is used.
<Sysname> system-view
[Sysname] vlan 10
[Sysname-vlan10] port gigabitethernet 2/1/4
# Verify that you cannot enter GigabitEthernet 2/1/2 interface view.
<Sysname> system-view
[Sysname] interface gigabitethernet 2/1/2
Permission denied.
Related commands
display role
interface policy deny
role

permit vlan

Use permit vlan to configure a list of VLANs accessible to a user role.
Use undo permit vlan to remove the permission for a user role to access specific VLANs.
Syntax
permit vlan vlan-id-list
undo permit vlan [ vlan-id-list ]
Default
No permitted VLANs are configured in user role interface policy view.
Views
User role VLAN policy view
Predefined user roles
network-admin
Parameters
vlan-id-list: Specifies a space-separated list of up to 10 VLAN items. Each VLAN item specifies a VLAN
by VLAN ID or specifies a range of VLANs in the form of vlan-id1 to vlan-id2. The value range for the
VLAN IDs is 1 to 4094. If you specify a VLAN range, vlan-id2 must be greater than vlan-id1.
Usage guidelines
To permit a user role to access a VLAN after you configure the vlan policy deny command, you must add
the VLAN to the permitted VLAN list of the policy. With the user role, you can perform the following tasks
on the VLANs in the permitted VLAN list:
Create, remove, or configure the VLANs.
Enter the VLAN views.
24

Advertisement

Table of Contents
loading

Table of Contents