User role policies are constrained by the rules defined for the role. For example, if you define an interface
policy to permit access to specific interfaces, the user does not have access to the interfaces unless you configure
a command rule for the role to permit the interface command.
If a command rule permits access to specific resources (interfaces, VLANs), the user is permitted to access
these resources, even if the user is not listed in the user role policies associated with that user.
User Account Configuration Restrictions
The following words are reserved and cannot be used to configure users:
•
adm
•
bin
•
daemon
•
ftp
•
ftpuser
•
games
•
gdm
•
gopher
•
halt
•
lp
•
mail
•
mailnull
•
man
•
mtsuser
•
news
•
nobody
•
san-admin
•
shutdown
•
sync
•
sys
•
uucp
•
xfs
Caution
Cisco Nexus 3548 Switch NX-OS System Management Configuration Guide, Release 6.x
23
Configuring User Accounts and RBAC
User Account Configuration Restrictions