You can configure IETF-NACM authorization to authorize specific users to perform NETCONF operations or access NETCONF resources. This ensures device security.
NACM authorization is an IETF-defined, more flexible authorization mode. It allows you to define NACM authorization rules to control specific users' permissions for performing NETCONF operations and accessing NETCONF resources.
The system view is displayed.
The NETCONF view is displayed.
The NACM view is displayed.
The NACM function is enabled.
Users are enabled to perform query operations.
Users are enabled to perform configuration operations.
Users are enabled to have the default execution permission for RPC operations.
An NACM user group is created, and the NACM user group view is displayed.
A user is specified for the NACM user group.
Exit the NACM user group view.
An NACM rule list is created, and the NACM rule list view is displayed.
The NACM user group is associated with the NACM authorization rule list.
A name is set for an NACM authorization rule in the NACM authorization rule list view.
A description is configured for the NACM authorization rule.
The name of a feature module is specified in the NACM authorization rule.
A type is specified for the NACM authorization rule.
Access operations are configured.
The configuration is committed.