cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
636
Views
0
Helpful
1
Replies

ACE module RBAC

Sergey Fuklev
Level 1
Level 1

Good day.

I have a question about RBAC on Cisco ACE.

Is it a possible create user role, whitch allowed monitor serverfarm state ("show serverfarm xxx" {detail} command), but restrict "show running/startup config" commands?

Configuration like following did not work (show commands not available):

role tst

    rule 1 permit monitor feature serverfarm

    rule 2 deny monitor

However Virtual Configuration Guide said ''The rule number determines the order in which the ACE applies the rules, with a higher-numbered rule applied after a lower-numbered rule''.

So it is possible to accomplished?

1 Reply 1

chrhiggi
Level 3
Level 3

Hello Anatoliy-

  Show run is permitted for all roles,/features, there is no way to disable it.

Regards,

  Chris Higgins

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: