Configuring The Vpn Instance Policy Of A User Role; Assigning User Roles; Enabling The Default User Role Feature - HP 10500 Series Configuration Manual

Hide thumbs Also See for 10500 Series:
Table of Contents

Advertisement

Configuring the VPN instance policy of a user role

Step
1.
Enter system view.
2.
Enter user role view.
3.
Enter user role VPN
instance policy view.
4.
(Optional.) Specify a list of
VPN instances accessible to
the user role.

Assigning user roles

To control user access to the system, you must assign a minimum of one user role. Make sure a minimum
of one user role among the user roles assigned by the server exists on the device. User role assignment
procedure varies for remote AAA authentication users, local AAA authentication users, and non-AAA
authentication users (see
Security Configuration Guide.

Enabling the default user role feature

The default user role feature allows AAA-authenticated users to access the system if the AAA server does
not authorize any user roles to the users.
This feature enables AAA-authenticated users that have not been assigned any user role to log in with the
default user role.
For login to the default MDC, the default user role is network-operator.
For login to a non-default MDC, the default user role is mdc-operator.
To enable the default user role feature for AAA authentication users:
Step
1.
Enter system view.
2.
Enable the default user role
feature.
Command
system-view
role name role-name
vpn-instance policy deny
permit vpn-instance
vpn-instance-name&<1-10>
"User role
assignment"). For more information about AAA authentication, see
Command
system-view
role default-role enable
23
Remarks
N/A
N/A
By default, the VPN instance policy of
the user role permits access to all VPN
instances.
This command denies the access of the
user role to all VPN instances if the
permit vpn-instance command is not
configured.
By default, no accessible VPN
instances are configured in user role
VPN instance policy view.
Repeat this step to add more
accessible VPN instances.
Remarks
N/A
By default, the default user role feature
is disabled.
If the none authorization method is
used for local users, you must enable
the default user role feature.

Advertisement

Table of Contents
loading

Table of Contents