Common Roles
Use the show role status command to display whether distribution is enabled for role configuration, the
current fabric status (locked or unlocked), and the last operation performed. See the following example.
Displays the Role Status Information
switch# show role status
Distribution: Enabled
Session State: Locked
Last operation (initiated from this switch): Distribution enable
Last operation status: Success
Use the show role pending command to display the pending role database.
The following example displays the output of the show role pending command by following this procedure:
1. Create the role called myrole using the role name myrole command.
2. Enter the rule 1 permit config feature fspf command.
3. Enter the show role pending command to see the output.
Displays Information on the Pending Roles Database
switch# show role pending
Role: network-admin
Description: Predefined Network Admin group. This role cannot be modified
Access to all the switch commands
Role: network-operator
Description: Predefined Network Operator group. This role cannot be modified
Access to Show commands and selected Exec commands
Role: svc-admin
Description: Predefined SVC Admin group. This role cannot be modified
Access to all SAN Volume Controller commands
Role: svc-operator
Description: Predefined SVC Operator group. This role cannot be modified
Access to selected SAN Volume Controller commands
Role: TechDocs
vsan policy: permit (default)
Role: sangroup
Description: SAN management group
vsan policy: deny
Permitted vsans: 10-30
---------------------------------------------
Rule
---------------------------------------------
1.
2.
3.
4.
Role: myrole
vsan policy: permit (default)
---------------------------------------------
Rule
---------------------------------------------
1.
Use the show role pending-diff command to display the differences between the pending and configuration
role database. See the following example.
Displays the Differences Between the Two Databases
switch# show role pending-diff
+Role: myrole
+
+
Type
Command-type
permit
config
deny
config
permit
debug
permit
exec
Type
Command-type
permit
config
vsan policy: permit (default)
---------------------------------------------
Displaying Roles When Distribution is Enabled
Feature
*
fspf
zone
fcping
Feature
fspf
Cisco MDS 9000 Series Security Configuration Guide, Release 8.x
21