group = netsupport {
default service = deny
acl = default
service = exec {
priv-lvl = 0
}
cmd = enable {
permit .*
}
cmd = show {
permit .*
}
cmd = exit {
permit .*
}
cmd = configure {
permit .*
}
cmd = interface {
permit Ethernet.*
permit FastEthernet.*
permit GigabitEthernet.*
}
cmd = switchport {
permit "access vlan.*"
permit "voice vlan.*"
permit "trunk allowed vlan.*"
}
cmd = description {
permit .*
}
cmd = no {
permit shutdown
}
}
above are permission I want to assign to support team to change configure on switch.
The problem is that when I allow them to use configure terminal command.
cmd = configure {
permit .*
}
Then they can do any thing on interface such as shutdwon interface, change mode on interface etc... and bellow permission is not effect.
cmd = switchport {
permit "access vlan.*"
permit "voice vlan.*"
permit "trunk allowed vlan.*"
}
as I want then can change VLAN only. I don't want to change port mode to access or trunk or shutdown vlan.
any help will be appreciate.
Thanks and regards,
Ratha