Rules; User Role Policies - Cisco Nexus 3548 series Configuration Manual

Nx-os system management, release 7.x
Hide thumbs Also See for Nexus 3548 series:
Table of Contents

Advertisement

Rules

Note
If you belong to multiple roles, you can execute a combination of all the commands permitted by these roles.
Access to a command takes priority over being denied access to a command. For example, suppose a user has
RoleA, which denied access to the configuration commands. However, the user also has RoleB, which has
access to the configuration commands. In this case, the user has access to the configuration commands.
Note
Only network-admin user can perform a Checkpoint or Rollback in the RBAC roles. Though other users have
these commands as a permit rule in their role, the user access is denied when you try to execute these commands.
Rules
The rule is the basic element of a role. A rule defines what operations the role allows the user to perform. You
can apply rules for the following parameters:
Command
Feature
Feature group
These parameters create a hierarchical relationship. The most basic control parameter is the command. The
next control parameter is the feature, which represents all commands associated with the feature. The last
control parameter is the feature group. The feature group combines related features and allows you to easily
manage the rules.
You can configure up to 256 rules for each role. The user-specified rule number determines the order in which
the rules are applied. Rules are applied in descending order. For example, if a role has three rules, rule 3 is
applied before rule 2, which is applied before rule 1.

User Role Policies

You can define user role policies to limit the switch resources that the user can access, or to limit access to
interfaces, VLANs, and VSANs.
User role policies are constrained by the rules defined for the role. For example, if you define an interface
policy to permit access to specific interfaces, the user does not have access to the interfaces unless you configure
a command rule for the role to permit the interface command.
If a command rule permits access to specific resources (interfaces, VLANs), the user is permitted to access
these resources, even if the user is not listed in the user role policies associated with that user.
Cisco Nexus 3548 Switch NX-OS System Management Configuration Guide, Release 7.x
202
A command or group of commands defined in a regular expression.
Commands that apply to a function provided by the Cisco Nexus device. Enter the show role feature
command to display the feature names available for this parameter.
Default or user-defined group of features. Enter the show role feature-group command to display the
default feature groups available for this parameter.
Configuring User Accounts and RBAC

Advertisement

Table of Contents
loading

Table of Contents