< Home

user (security policy rule view)

Function

The user command configures the user to which a security policy rule applies.

The undo user command deletes the user to which a security policy rule applies.

Format

user { username user-name &<1-6> | user-group user-group-name &<1-6> | security-group security-group-name &<1-6> | any }

undo user { username user-name &<1-6> | user-group user-group-name &<1-6> | security-group security-group-name &<1-6> | all }

Parameters

Parameter Description Value

username user-name &<1-6>

Specifies the name of a user.

The specified user must exist. A maximum of six users can be created or deleted at a time.

When a user in a non-default authentication domain is specified, the user name must carry "@authentication-domain-name." For example, user1@test indicates user1 in the test authentication domain.

user-group user-group-name &<1-6>

Specifies the name of a user group.

The user group must already exist. A maximum of six user groups can be created or deleted at a time.

A user group name must carry the authentication domain name. For example, /default/group1 indicates group1 in the default authentication domain.

security-group security-group-name &<1-6>

Specifies the name of a security group.

The security group must already exist. A maximum of six security groups can be created or deleted at a time.

When a security group in a non-default authentication domain is specified, the security group name must carry "@authentication-domain-name." For example, secgroup@test indicates security group secgroup in the test authentication domain.

any

Indicates any user to which a security policy rule applies.

-

all

Deletes all users to which a security policy rule applies.

-

Views

Security policy rule view

Default Level

2: Configuration level

Usage Guidelines

The firewall obtains user login information by monitoring AD authentication packets and configures security policies for users to access the Internet. If the firewall cannot obtain user logout information, the firewall cannot quickly log out users using security policies.

Example

# Apply security policy rule policy_sec to user group /default/managers.

<sysname> system-view
[sysname] security-policy
[sysname-policy-security] rule name policy_sec
[sysname-policy-security-rule-policy_sec] user user-group /default/managers
Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
< Previous topic Next topic >