Managing SSL VPN Permissions
    • PDF

    Managing SSL VPN Permissions

    • PDF

    Article Summary

    Available in VPC

    By using Sub Account, NAVER Cloud Platform's account management service, you can set various access permissions for SSL VPN. Sub Account provides System Managed policies and User Created policies for setting management and administration permissions.

    Note

    Sub Account is a service provided free of charge upon subscription request. For more details about Sub Account, see the Services > Management & Governance > Sub Account menu in the NAVER Cloud Platform portal, as well as the Sub Account guide.

    System managed policies

    System Managed policies are role-based policies defined by NAVER Cloud Platform for user convenience. Once System Managed policies are granted to a sub account created in Sub Account that sub account can use SSL VPN. The following is a brief description about System Managed policies of SSL VPN.

    Policy namePolicy description
    NCP_INFRA_MANAGERPermission to use all services in NAVER Cloud Platform and access My Page > Manage notifications in the portal
    NCP_VPC_SSLVPN_MANAGERPermission to use all the features in VPC-based SSL VPN
    NCP_VPC_SSLVPN_VIEWERPermission to only view items and their details in VPC-based SSL VPN

    User Created policies

    User-defined policies are policies that users may directly create. Once User Created policies are granted to a sub account created in Sub Account, that sub account can only use the user-assigned action combinations.
    The following is a brief description about user created policies.

    TypeAction nameRelated action(s)Resource typeGroup by resource typeAction description
    ViewView/getSSLVPNList--SSLVPNView SSLVPN list
    ViewView/getSSLVPNDetailView/getSSLVPNListSSLVPNSSLVPNView SSLVPN details
    ViewView/getVPCList--VPCView VPC list to create SSLVPN
    ViewView/getVPCDetailView/getVPCListVPCVPCView VPC details to create SSLVPN
    ChangeChange/createSSLVPNView/getVPCList
    View/getVPCDetail
    View/getSSLVPNList
    -SSLVPNCreate SSLVPN
    ChangeChange/deleteSSLVPNView/getSSLVPNList
    View/getSSLVPNDetail
    SSLVPNSSLVPNDelete SSLVPN
    ChangeChange/updateSSLVPNSpecView/getSSLVPNList
    View/getSSLVPNDetail
    SSLVPNSSLVPNEdit SSLVPN
    ChangeChange/updateSSLVPNDescriptionView/getSSLVPNList
    View/getSSLVPNDetail
    SSLVPNSSLVPNChange SSLVPN memo
    ChangeChange/manageSSLVPNUserView/getSSLVPNList
    View/getSSLVPNDetail
    SSLVPNSSLVPNEdit SSLVPN user information
    ChangeChange/manageSSLVPNUserConfigurationChange/manageSSLVPNUserSSLVPNUserSSLVPNUserEdit SSLVPN user access information
    ChangeChange/createSSLVPNUserConfigurationChange/manageSSLVPNUserSSLVPNSSLVPNUserAdd SSLVPN user access information
    ChangeChange/updateSSLVPNAuthlogChange/updateSSLVPNSpecSSLVPNSSLVPNCLA connection for collecting Authlog
    Caution

    Even when you are granted permission for a specific action, if you are not also granted permissions for the related actions that are required, then you won't be able to perform jobs properly. To prevent such issues, Sub Account provides a feature that automatically grants permissions for related actions when granting action permissions. However, if you deselect related actions that are automatically granted, then the system determines that it was done intentionally by the main account user and does not forcibly include them. Thus, be careful when setting permissions.


    Was this article helpful?

    Changing your password will log you out immediately. Use the new password to log back in.
    First name must have atleast 2 characters. Numbers and special characters are not allowed.
    Last name must have atleast 1 characters. Numbers and special characters are not allowed.
    Enter a valid email
    Enter a valid password
    Your profile has been successfully updated.