Modifying The Vsan Policy; Role Distributions - Cisco AP776A - Nexus Converged Network Switch 5020 Configuration Manual

Cisco mds 9000 family cli configuration guide - release 4.x (ol-18084-01, february 2009)
Hide thumbs Also See for AP776A - Nexus Converged Network Switch 5020:
Table of Contents

Advertisement

Role Distributions

S e n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a c k - d o c @ c i s c o . c o m
Roles can be used to create VSAN administrators. Depending on the configured rules, these VSAN
Tip
administrators can configure MDS features (for example, zone, fcdomain, or VSAN properties) for their
VSANs without affecting other VSANs. Also, if the role permits operations in multiple VSANs, then the
VSAN administrators can change VSAN membership of F or FL ports among these VSANs.
Users belonging to roles in which the VSAN policy is set to deny are referred to as VSAN-restricted
users.

Modifying the VSAN Policy

To modify the VSAN policy for an existing role, follow these steps:
Command
Step 1
switch# config t
Step 2
switch(config)# role name sangroup
switch(config-role)#
Step 3
switch(config)# vsan policy deny
switch(config-role-vsan)
switch(config-role)# no vsan policy
deny
Step 4
switch(config-role-vsan)# permit vsan
10-30
switch(config-role-vsan)# no permit
vsan 15-20
Role Distributions
Role-based configurations use the Cisco Fabric Services (CFS) infrastructure to enable efficient
database management and to provide a single point of configuration for the entire fabric (see
"Using the CFS
The following configurations are distributed:
This section includes the following topics:
Cisco MDS 9000 Family CLI Configuration Guide
32-4
Infrastructure").
Role names and descriptions
List of rules for the roles
VSAN policy and the list of permitted VSANs
About Role Databases, page 32-5
Locking the Fabric, page 32-5
Committing Role-Based Configuration Changes, page 32-5
Discarding Role-Based Configuration Changes, page 32-5
Enabling Role-Based Configuration Distribution, page 32-6
Chapter 32
Purpose
Enters configuration mode.
Places you in role configuration submode for the sangroup
role.
Changes the VSAN policy of this role to deny and places
you in a submode where VSANs can be selectively
permitted.
Deletes the configured VSAN role policy and reverts to
the factory default (permit).
Permits this role to perform the allowed commands for
VSANs 10 through 30.
Removes the permission for this role to perform
commands for VSANs 15 to 20. So, the role is now
permitted to perform commands for VSAN 10 to 14, and
21 to 30.
OL-18084-01, Cisco MDS NX-OS Release 4.x
Configuring Users and Common Roles
Chapter 7,

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents