cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements

468
Views
0
Helpful
0
Replies
Highlighted
Beginner

Nexus 7K limited config role

I need to create a role in a 7K version 6.2(16) for a server admin to be able to add and remove one variation of a route (in the middle of the night, so I don't want to get up unless he calls me if it all goes wrong).

The commands he needs to be able to execute are:

ip route 10.11.20.23/32 10.10.10.26 tag 10
ip route 10.11.20.23/32 10.10.10.27 tag 10
no ip route 10.11.20.23/32 10.10.10.26 tag 10
no ip route 10.11.20.23/32 10.10.10.27 tag 10

I fiddled with roles a little, but it's not straightforward how to make this happen. Here's what I have:

 

role name serveradmin
rule 10 permit command config t
rule 1 permit command ip route 10.11.20.23/32 10.10.10.2[67] tag 10
rule 2 permit command no ip route 10.11.20.23/32 10.10.10.2[67] tag 10

It said it supported regex, so I figured I'd just go for that.

Once I go into "config t"I don't have any options. I'm guessing "command" means exec mode and doesn't count for config mode. However, I don't see a way to do anything for config mode besides read-write features, ip routing not being one of those. Any suggestions?

Everyone's tags (2)
CreatePlease to create content
Content for Community-Ad
July's Community Spotlight Awards