20
sys-15 permit command undelete *
sys-16 permit command ftp *
sys-17 permit command sftp *
R:Read W:Write X:Execute
Role: guest-manager
Description: Predefined guest manager role can't access to commands
VLAN policy: permit (default)
Interface policy: permit (default)
VPN instance policy: permit (default)
-------------------------------------------------------------------
Rule Perm Type Scope Entity
-------------------------------------------------------------------
sys-1 permit RWX xml-element useraccounts/approveguest/
sys-2 permit RWX xml-element useraccounts/exportguestaccount/
sys-3 permit RWX xml-element useraccounts/generateguestaccoun
t/
sys-4 permit RWX xml-element useraccounts/guest/
sys-5 permit RWX xml-element useraccounts/guestconfigure/
sys-6 permit RWX xml-element useraccounts/importguestaccount/
sys-7 permit RWX xml-element useraccounts/exportguesttemplet/
sys-8 permit RWX xml-element rpc/
sys-9 deny command *
R:Read W:Write X:Execute
Table 3 Command output
Field Description
Role
User role name.
Predefined user role names:
• network-admin.
• network-operator.
• level-n (where n represents an integer in the range of 0 to 15).
• security-audit.
• guest-manager. This user role is not supported in the current
software version.
Description User role description.
VLAN policy
VLAN policy of the user role:
• deny—Denies access to all VLANs except for permitted
VLANs.
• permit (default)—Default VLAN policy, which enables the user
role to access all VLANs.
Permitted VLANs VLANs accessible to the user role.
Interface policy
Interface policy of the user role:
• deny—Denies access to all interfaces except for permitted
interfaces.
• permit (default)—Default interface policy, which enables the
user role to access all interfaces.
Permitted interfaces Interfaces accessible to the user role.