Policy-Group; Port-Forward - H3C MSR Series Command Reference Manual

Comware 7 security
Hide thumbs Also See for MSR Series:
Table of Contents

Advertisement

Related commands
new-content

policy-group

Use policy-group to create an SSL VPN policy group and enter its view, or enter the view of an
existing SSL VPN policy group.
Use undo policy-group to delete a policy group.
Syntax
policy-group group-name
undo policy-group group-name
Default
No SSL VPN policy groups exist.
Views
SSL VPN context view
Predefined user roles
network-admin
Parameters
group-name: Specifies a name for the policy group, a case-insensitive string of 1 to 31 characters.
Usage guidelines
An SSL VPN policy group contains a set of rules for resource access authorization.
You can configure multiple SSL VPN policy groups for an SSL VPN context. When a remote user
accesses the SSL VPN context, the AAA server issues the authorized policy group to the associated
SSL VPN gateway. The user can access only the resources allowed by the authorized policy group.
If the AAA server does not authorize the user to use a policy group, the user can access only the
resources allowed by the default policy group.
Examples
# Create a policy group named pg1 and enter its view.
<Sysname> system-view
[Sysname] sslvpn context ctx1
[Sysname-sslvpn-context-ctx1] policy-group pg1
[Sysname-sslvpn-context-ctx1-policy-group-pg1]
Related commands
default-policy-group

port-forward

Use port-forward to create a port forwarding list for an SSL VPN context and enter its view, or enter
the view of an existing port forwarding list.
Use undo port-forward to delete a port forwarding list.
Syntax
port-forward port-forward-name
undo port-forward port-forward-name
783

Advertisement

Table of Contents
loading

Table of Contents