17
Ridgeline Concepts and Solutions Guide
253
Figure 200: Role Hierarchy
Role Inheritance
Child roles inherit the policies of the parent role in the hierarchy. When an identity is assigned to a role,
the policies and rules defined by that role and all higher roles in the hierarchy are applied.
When the parent role is deleted or when the parent-child relationship is deleted, the child role no longer
inherits the parent role's policies and the policies are immediately removed from all identities mapped
to the child role.
Since the maximum role hierarchy depth allowed is 5 levels, the maximum number of policies and
dynamic ACLs that can be applied to a role is 40 (5 role levels x 8 policies/rules per role).
NOTE
The LDAP query can be disabled for specific types of netlogin users.
When the software makes the final determination of which default or user configured role applies to the
identity, the policies and rules configured for that role are applied to the port to which the identity is
attached. This feature supports up to 8 policies and dynamic ACL rules per role.
The identity's IP address is used to apply the dynamic ACLs and policies. The dynamic ACLs or
policies that are associated to roles should not have any source IP address specified because the identity
management feature will dynamically insert the identity's IP address as the source IP address. When a
dynamic ACL or policy is added to a role, it is immediately installed for all identities mapped to that
role. Effective configuration of the dynamic ACLs and policies will ensure that intruders are avoided at
the port of entry on the edge switch, thereby reducing noise in the network.
EX_roles_01
Parent role
Children roles
Supports
five levels
Summary of Contents for Ridgeline 3.0
Page 14: ...Related Publications Ridgeline Concepts and Solutions Guide 12 ...
Page 26: ...Ridgeline Overview Ridgeline Concepts and Solutions Guide 24 ...
Page 52: ...Getting Started with Ridgeline Ridgeline Concepts and Solutions Guide 50 ...
Page 78: ...Using Map Views Ridgeline Concepts and Solutions Guide 76 ...
Page 88: ...Provisioning Network Resources Ridgeline Concepts and Solutions Guide 86 ...
Page 103: ...6 Ridgeline Concepts and Solutions Guide 101 Figure 63 E Line Service Details Window ...
Page 104: ...Managing Ethernet Services Ridgeline Concepts and Solutions Guide 102 ...
Page 114: ...Importing Services Ridgeline Concepts and Solutions Guide 112 ...
Page 132: ...Managing and Monitoring VPLS Domains Ridgeline Concepts and Solutions Guide 130 ...
Page 146: ...Managing VLANs Ridgeline Concepts and Solutions Guide 144 ...
Page 190: ...Managing Your EAPS Configuration Ridgeline Concepts and Solutions Guide 188 ...
Page 202: ...Managing Network Security Ridgeline Concepts and Solutions Guide 200 ...
Page 350: ...Book Title Ridgeline Concepts and Solutions Guide 348 ...
Page 372: ...Book Title Ridgeline Concepts and Solutions Guide 370 ...