
User and Group Management
permissions for cluster “Cl2”. The next step is to add specific permissions on the Equalizer
objects within each cluster for each user.
Object Permissions for Each User
Setup the object permissions for users “Touch_1” and “Touch_2”. Use "Required Task Permissions and Flags" on
page 501"Required Task Permissions and Flags" on page 501as a guideline.
1. Create “read” and “write” permissions for user “Touch_1” on VLAN “vl1”.
eqcli > user Touch_1 permit_object read,write vlan vl1
2. Create “read” and “write” permissions for user “Touch_2” on VLAN “vl2”.
eqcli > user Touch_2 permit_object read,write vlan vl2
3. Create “read”, “write” and “delete” permissions for user “Touch_1” on “testserverpool1”.
eqcli > user Touch_1 permit_object read,write,delete srvpool testserverpool1
4. Create “read”, “write” and “delete” permissions for user “Touch_2” on “testserverpool2”.
eqcli > user Touch_1 permit_object read,write,delete srvpool testserverpool2
5. Create “read”, “write” and “delete” permissions for user “Touch_1” on servers “test1” and “test2”.
eqcli > user Touch_1 permit_object read,write,delete server test1
eqcli > user Touch_1 permit_object read,write,delete server test2
6. Create “read”, “write” and “delete” permissions for user “Touch_2” on servers “test3” and “test4”.
eqcli > user Touch_2 permit_object read,write,delete server test3
eqcli > user Touch_1 permit_object read,write,delete server test4
Permissions have now been configured for users “Touch_1” and “Touch_2”. Each has access to 1 cluster and
access with permissions on VLANS, Servers and Server Pools within the cluster. To view the permissions enter
the following:
eqcli > show user Touch_1
508
Copyright © 2013 Coyote Point Systems. A subsidiary of Fortinet, Inc.
Comentarios a estos manuales