beautypg.com

User requirements – Brocade Virtual ADX Administration Guide (Supporting ADX v03.1.00) User Manual

Page 116

background image

Brocade Virtual ADX Administration Guide

104

53-1003249-01

Overview of Role Based Management

3

User requirements

A maximum of 1024 users can be created on a Brocade Virtual ADX. There are four levels of user
privileges:

0 - For a super user who is given all privileges. A manager has operator and viewer privileges
for the specific administrative domain.
The commands that can be executed only by super users are:

-

copy

-

boot

-

reload

-

asm

-

rconsole

-

show server debug

-

show users

The following items can be created, deleted, or configured only by super users:

-

Username

-

Context

-

Role template

1 - The new privilege level. The role-based policy controls access to level 1. Depending on the
configuration, a privilege level 1 user can perform the following functions:

-

View global configurations

-

Manage global configurations

-

Manage one or more contexts

-

Operate one or more contexts

-

View one or more contexts

4 - For port configuration.

5 - For read access. The operator and manager have viewer privileges for the specific domain.

To simplify the configuration, the super user can create role templates first and associate the
templates with sets of privileges. The available privileges are the same as the user level
configurations. The user privilege takes effect immediately when the privileges for a user are
changed after the user login. A user can then be associated with and granted privileges in the
template. The user level privileges that can be configured to overwrite the privileges in the template
consist of the following:

The user has no privileges for the domain if no privilege is granted for an administrative
domain at both the template and user levels.

The user level privilege takes precedence if a privilege is granted both at the template and user
levels.

The user inherits the privilege from the template if a privilege is granted only at the template
level.

The user has the configured privileges if a privilege is granted only at the user level.