cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements
AMA event- Migrating Existing Networks to Cisco ACI
480
Views
0
Helpful
1
Replies
Highlighted
Beginner

ACE module RBAC

Good day.

I have a question about RBAC on Cisco ACE.

Is it a possible create user role, whitch allowed monitor serverfarm state ("show serverfarm xxx" {detail} command), but restrict "show running/startup config" commands?

Configuration like following did not work (show commands not available):

role tst

    rule 1 permit monitor feature serverfarm

    rule 2 deny monitor

However Virtual Configuration Guide said ''The rule number determines the order in which the ACE applies the rules, with a higher-numbered rule applied after a lower-numbered rule''.

So it is possible to accomplished?

Everyone's tags (1)
1 REPLY 1
Participant

ACE module RBAC

Hello Anatoliy-

  Show run is permitted for all roles,/features, there is no way to disable it.

Regards,

  Chris Higgins

CreatePlease to create content
Content for Community-Ad
August's Community Spotlight Awards