Owner's Manual

98 Security
-
Role
— Within this application, objects can refer to a role. The role can describe the use those
objects have within the network — core router, for example, as opposed to edge router.
NOTE:
You cannot make individual interfaces part of an object group, but you can assign a role to them. Roles
make natural groups, and you can use those role-based groups to manage the access to individual
interfaces.
The system administrator and add-on products can add other groups to this list, and can add
objects to those groups.
To add a new object group, click
New
below the list of available groups and name the group in the
subsequent screen. Accept that name to add it to those listed.
CAUTION:
All users inherit OWPublic's permissions. You must remove OWPublic's read permissions from things in
Object Group Manager to conceal those items.
Adding or Modifying Object Groups
When you click
New
, you can create a new association between either user or object groups and
permissions. Select from
User Groups
(see User Group Manager on page 77 for instructions about
how to make and manage these groups) or individual users (see User Manager on page 69 for more
information about these). The button at the top right of this screen toggles between individual
users and groups displayed in the pick list in the top center of the screen (Figure 4-19).