07-08-2009 02:05 PM - edited 03-06-2019 06:39 AM
Hi,
I was wondering if it is possible to give a privilege access and let a person only put a specific vlan ID on the switch port but not all VLAN IDs available on the switch.
This is because I had DMZs on the LAN switch, and I don't want to give access to techs to put the VLAN ID of a DMZ, only they can change on LAN VLAN ID.
THanks !
Martin
07-08-2009 02:16 PM
Martin
I do not know of any way to give a user privilege access to change VLAN ID and then to restrict which VLAN that they change.
HTH
Rick
07-08-2009 05:40 PM
Hi Martin,
I agree with Rick.
It seems hardly to implement it if you only presume upon the LAN switch itself.
I suppose set allowed vlan on trunk links to the DMZ LAN switch maybe can archieve your object. But the precondition is the VLANs must not be used at all.
Or depend on some other network management application which can be set permission by more specific condition, such as vlan id.
Hope to help.
Wandering
07-08-2009 06:00 PM
Hi Martin,
You should be able to achive this using role based CLI access. You can lock a view down to specific commands.
See this link:
HTH,
Andres
07-09-2009 06:26 AM
Thanks a lot for your answers, I believed I can't like you, but this parser that Andres proposed could work, I didn't know it before. I will check that info.
Thanks a lot again !
Martin
07-09-2009 06:41 AM
Unfortunately, it is only supported from 12.4 on routers but not for switches ;)
Thanks a lot anyway,
Martin
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide