
User and Group Management
Best User and Group Management
Practices
When adding additional users and groups to your configuration, follow these guidelines to establish object
permissions that will be effective and easy to manage:
If you require multiple non-admin users in your configuration, it is preferable to first create all required objects
(servers, server pools, clusters, etc.), and then create users with appropriate permissions to manage them.
In the easiest to manage scenario:
l There is one user with the "admin" flag set.
l The "admin" user creates all objects.
l The "admin" user assigns users "read", "write", and "delete" permissions on objects in the configuration (as
necessary) so that those users can perform required tasks on those objects (see Table).
l A user can be given permission to perform certain administrative tasks by enabling the "read_global" and
"write_global" flags for that user (See "User Flags" on page 182).
l No groups other than "Default" are used.
The next step up in complexity is to give a non-admin user the ability to create objects of a particular type.
An even more advanced mode allows users to create objects of a certain type and add them to a group other than
"Default" as well. In this scenario, an "admin" user must update the users "permit" list to give the non-admin user
access to any new objects the non-admin user creates.
In general, it is recommended that the "admin" flag and the "create" permission are enabled for as few users as
possible. Otherwise, chaos may ensue. You have been warned!
Note - By default Equalizer comes with an admin user “touch”. User permissions can only be assigned by an
administrator using the eqcli command line interface.
Object Permission Types
The following are the permissions available on Equalizer objects:
Permission Type Descriptions
Read
The user can only view the object’s definition.
For global parameters: the user can open all of the global parameter tabs displayed when you click on
Equalizer in the left frame, but cannot use the commit button to make any changes.
For clusters: cluster definitions for which the user has read permission are displayed in the left frame
and all globaltabs. The user can select clusters and view their definitions.
500
Copyright © 2013 Coyote Point Systems. A subsidiary of Fortinet, Inc.
Kommentare zu diesen Handbüchern