Juniper NETWORK AND SECURITY MANAGER 2010.4 - ADMININISTRATION GUIDE REV1 Administration Manual page 461

Table of Contents

Advertisement

User Groups
OR
AND
NOT
Group Expressions
OR
AND
NOT
Copyright © 2010, Juniper Networks, Inc.
Table 40: Group Expression Operators (continued)
User Objects
If the security policy defines authentication for user group " a" or user group " b"
, the security device authenticates the user if it belongs to either " a" or " b" user
group.
If the security policy defines authentication for user group " a" AND user group "b"
, the security device authenticates the user only if it belongs to both user groups.
If the security policy defines authentication for any user group that is not group
"c" (NOT "c" ), the security device authenticates all users except those that belong
to the "c" user group.
If the security policy defines authentication for user objects that match the
description of group expression "a" OR group expression "b" , the security device
authenticates the user if either group expression references that user.
If the security policy defines authentication for user objects that match the
description of group expression "a" AND group expression "b," the security device
authenticates the user only if both group expressions reference that user.
If the security policy defines authentication for user objects that do not match
the description of group expression "c" (NOT "c" ), the security device
authenticates all users except those that match the group expression.
Because a group expression references external user objects and external user groups,
you must first create those user object and groups before you can use them in a group
expression. You cannot reference local user object or local user object groups in a group
expression.
To add a group expression:
In the navigation tree, double-click Object Manager and select Group Expressions.
1.
In the main display area, click the Add icon and select New. The New Group Expression
2.
dialog box appears.
Enter a name, color, and comment for the group expression.
3.
Select the operator you want to use in the expression (OR, AND, NOT) and then
4.
configure the operands:
Chapter 8: Configuring Objects
411

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the NETWORK AND SECURITY MANAGER 2010.4 - ADMININISTRATION GUIDE REV1 and is the answer not in the manual?

Questions and answers

Subscribe to Our Youtube Channel

This manual is also suitable for:

Network and security manager 2010.4

Table of Contents