# Doc error? : Setting up access to VNETs

**URL:** <https://forum.opennebula.io/t/doc-error-setting-up-access-to-vnets/1344>\
**Category:** Product Support\
**Created:** [October 18, 2015, 11:31pm UTC](https://forum.opennebula.io/t/doc-error-setting-up-access-to-vnets/1344 "2015-10-18T23:31:32Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![michaudg](https://avatars.discourse-cdn.com/v4/letter/m/e9a140/32.png) [@michaudg](https://forum.opennebula.io/u/michaudg)\
**Post date:** [October 18, 2015, 11:31pm UTC](https://forum.opennebula.io/t/doc-error-setting-up-access-to-vnets/1344/1 "2015-10-18T23:31:32Z")

</div>

[http://docs.opennebula.org/4.14/user/virtual\_resource\_management/vgg.html#setting-up-access-to-vnets](http://docs.opennebula.org/4.14/user/virtual_resource_management/vgg.html#setting-up-access-to-vnets)

The documentation specify that « Once a VNET is setup by a Cloud admin, she needs to make it available to other users in the cloud. […] Users can only attach VMs or make reservations from VNETs with USE rights on the VNET ».

But I finally found out why all users can use all VNETs created by oneadmin user even if the VNET ACL doesn’t grant other:use permission : there is a default entry in the ACL tab that grant use permission on all VNETs and Datastores for the default users group and for all new group created.

If this behavior is normal, I think the documentation is wrong.

---

<div class="post-metadata">

**Author:** ![cmartin](https://yyz1.discourse-cdn.com/flex031/user_avatar/forum.opennebula.io/cmartin/32/4278_2.png) [@cmartin](https://forum.opennebula.io/u/cmartin)\
**Post date:** [October 19, 2015, 1:54pm UTC](https://forum.opennebula.io/t/doc-error-setting-up-access-to-vnets/1344/2 "2015-10-19T13:54:33Z")

</div>

Hi,

Thank you for your comments, I’ve [opened a ticket](http://dev.opennebula.org/issues/4068) so we don’t forget about it.

Probably we should advise to assign the VNet to the group’s VDC. That creates internally the ACL rules needed.
