Authorizing user access to application resources
-
Rule. The resource to which access must be authorized. This can be specified by using basic or advanced expressions.
-
Action. Whether access to the resource must be allowed or denied.
To configure authorization by using the CLI
-
Configure the authorization policy.ns-cli-prompt\> add authorization policy \<name\> \<rule\> \<action\>
-
Associate the policy with the appropriate user or group.
-
Bind the policy to a specific user.ns-cli-prompt\> bind aaa user \<username\> -policy \<policyname\>
-
Bind the policy to a specific group.ns-cli-prompt\> bind aaa group \<groupName\> -policy \<policyname\>
-
To configure authorization by using the GUI (Configuration tab)
-
Create the authorization policy.Navigate to Security > AAA - Application Traffic > Policies > Authorization, click Add and then define the policy as required.
-
Associate the policy with the appropriate user or group.Navigate to Security > AAA - Application Traffic > Users or Groups, and edit the relevant user or group to associate it with the authorization policy.
Sample authorization configurations
add authorization policy authzpol1 "HTTP.REQ.URL.SUFFIX.EQ(\"gif\")" ALLOW
bind aaa user user1 -policy authzpol1
add authorization policy authzpol2 "HTTP.REQ.URL.SUFFIX.EQ(\"png\")" DENY
bind aaa group group1 -policy authzpol2