SSL VPN permissions management

Prev Next

Available in VPC

You can set different access permissions for SSL VPN using NAVER Cloud Platform's Sub Account service. Sub Account offers both system-managed (System Managed) and user-defined (User Created) policies to help you configure management and operation permissions.

Note

Sub Account is a free service with no additional charges. For more information about Sub Account, see Services > Management & Governance > Sub Account on the NAVER Cloud Platform portal and the Sub Account user guide.

System-managed policies

System-managed policies are pre-built, role-based policies that NAVER Cloud Platform provides for your convenience. When you assign one of these policies to a sub account that account gets access to SSL VPN. Here are the available system-managed policies for SSL VPN:

Policy name Policy description
NCP_ADMINISTRATOR Full access to all services, same as the main account
NCP_INFRA_MANAGER Access to all NAVER Cloud Platform services, except the My Account > Pricing information and cost management > Billing and payment management menu on the console
NCP_FINANCE_MANAGER Access to Cost Explorer and the My Account > Pricing information and cost management > Billing and payment management menu on the console
NCP_VPC_SSLVPN_MANAGER Full access to all SSL VPN features on the VPC platform
NCP_VPC_SSLVPN_VIEWER View-only access to all SSL VPN features on the VPC platform

User-defined policies

User-defined policies let you create custom permissions. When you assign a user-defined policy to a sub account, that account can only perform the specific actions you've allowed.
Here are the available user-defined policies for SSL VPN:

| Type | Action name | Related action | Resource type | Group by resource type | Action description |
| ---- | ---- | ---- | ---- | ---- | ---- |
| View | View/getSSLVPNList | - | - | SSLVPN | View SSLVPN list. |
| View | View/getSSLVPNDetail | View/getSSLVPNList | SSLVPN | SSLVPN | View SSLVPN details. |
| View | View/getVPCList | - | - | VPC | View list of VPC for creating SSLVPN. |
| View | View/getVPCDetail | View/getVPCList | VPC | VPC | View details of VPC for creating SSLVPN. |
| Change | Change/createSSLVPN | View/getVPCList
View/getVPCDetail
View/getSSLVPNList | - | SSLVPN | Create SSLVPN. |
| Change | Change/deleteSSLVPN | View/getSSLVPNList
View/getSSLVPNDetail | SSLVPN | SSLVPN | Delete SSLVPN. |
| Change | Change/updateSSLVPNSpec | View/getSSLVPNList
View/getSSLVPNDetail | SSLVPN | SSLVPN | Edit SSLVPN. |
| Change | Change/updateSSLVPNDescription | View/getSSLVPNList
View/getSSLVPNDetail | SSLVPN | SSLVPN | Change SSLVPN memo. |
| Change | Change/manageSSLVPNUser | View/getSSLVPNList
View/getSSLVPNDetail | SSLVPN | SSLVPN | Edit SSLVPN user information. |
| Change | Change/manageSSLVPNUserConfiguration | Change/manageSSLVPNUser | SSLVPNUser | SSLVPNUser | Edit SSLVPN user access information. |
| Change | Change/createSSLVPNUserConfiguration | Change/manageSSLVPNUser | SSLVPN | SSLVPNUser | Add SSLVPN user access information. |
| Change | Change/updateSSLVPNAuthlog | Change/updateSSLVPNSpec | SSLVPN | SSLVPN | Integrate with CLA for collecting Authlog. |

Caution

If you grant someone access to a specific action but not to the required related actions, they won't be able to complete their tasks. Sub Account automatically includes these related permissions to prevent this issue. However, if you manually uncheck these auto-selected related actions, the system assumes this was intentional and won't override your selection.