21
Field Description
VPN instance policy
VPN instance policy of the user role:
• deny—Denies access to all VPN instances except for permitted
VPN instances.
• permit (default)—Default VPN instance policy, which enables
the user role to access all VPN instances.
Permitted VPN instances VPN instances accessible to the user role.
Rule
User role rule number.
Predefined user role rules are identified by sys-n, where n represents
an integer.
Perm
Access control type:
• permit—User role has access to the items in the Entity field.
• deny—User role does not have access to the items in the
Entity field.
Type
Controlled type:
• R—Read-only.
• W—Write.
• X—Execute.
Scope
Rule control scope:
• command—Controls access to the command or commands, as
specified in the Entity field.
• feature—Controls access to the commands of the feature, as
specified in the Entity field.
• feature-group—Controls access to the commands of the
features in the feature group, as specified in the Entity field.
• web-menu—Controls access to Web menus. This rule control
scope is not supported in the current software version.
• xml-element—Controls access to XML elements.
• oid—Controls access to MIB nodes.
Entity
Command string, feature name, feature group, XML element, or OID
specified in the user role rule:
• An en dash (–) represents any feature.
• An asterisk (*) represents zero or more characters.
Related commands
role
display role feature
Use display role feature to display features available in the system.
Syntax
display role feature [ name feature-name | verbose ]
Views
Any view
Predefined user roles
network-admin
network-operator