Creating Group Security
Only a user with security privileges can create groups and provide them with network group security. Users with read/write and read-only privileges can perform functions only in the groups to which a user with security privileges assigns access. All groups that a security user creates participate in this network group security feature.
The NMC-RX application does not support security at the device level. To establish security for a particular device, the user with device administration privileges can create the device as a member of a group and apply a security setting and, if needed, a security filter to the group.
NOTE: Group security cannot be enforced at the CLI, because the E-series router itself does not have a group concept.
- From the Network Workshop, click the Juniper Networks icon in the upper-left corner of the context area.
![]()
- Right-click, select Create, and click Group.
The Create Group dialog box appears.
![]()
- Set the Create Group parameters (Table 34).
- Select a Security Setting option (Table 35).
NOTE: The access list for a group is derived by filtering the access lists from the top level of the navigational tree down to the given group.
If the group is a top-level group and you select None, the Allowed Users list contains all the users configured for the NMC-RX application. If the group is the child of a parent group and you select None, the Allowed Users list contains all of the users that have access to the parent group.
If you select None, the Insert/Remove Users button is disabled. If you select either Permit or Deny, the Insert/Remove Users button is enabled, which lets you create a filter list of users who are permitted or denied access to the group.
The Create Group Security - Insert/Remove Users dialog box appears. In this dialog box, you can display a list of users for either the parent group or the entire system. From this list, you can create a filtered list of users with access to the group (or subgroup) that you are creating.
![]()
- To create a filter list for the group, individually select the users in the Available Users list, and click the Add button to add the users to the Filter List.
- To add the entire list of available users to the Filter List, click the Add All button.
- To remove users from the Filter List individually or collectively, either select a user in the Filter List and click Remove, or click Remove All.
The dialog box closes, and the Create Group dialog box appears. The filter list of users is displayed in the Security Filter list.
The new group name and folder icon appear in the list in the context area of the Network Workshop.
NOTE: If you set security to Deny access but do not add at least one user in the Security Filter list, an error message appears.