Learn how to assign a fabric node to a security domain.
Using an RBAC node rule, the fabric administrator can assign a physical node, such as a leaf switch, to a security domain. This node assignment allows a user in that security domain to access and perform operations on a node assigned as part of the node rule. Only a user with node management privileges within the security domain can configure nodes assigned to that domain. The user has no access to nodes outside of the security domain, and users in other security domains have no access to the node assigned to the security domain. To create or modify configurations on a node assigned to the security domain, a user in that domain must also be assigned to domain all with the port-mgmt role that contains the custom-port-privilege privilege by default or a custom role that contains the custom-port-privilege privilege.
When configuring a local user who will manage ports on an assigned node, you must grant the user a role in domain all, and theadminrole in the security domain to which the node is assigned. Both roles must have the Role Privilege Type configured asWrite.