Cisco APIC Security Configuration Guide, Release 5.2(x) - AV Pair on the External Authentication Server --------------------------------------- Starting with release 3.1(x), the AV Pair shell:domains=all//admin allows you to assign Read-only privileges to users and provide them access to the switches and run commands. <-snip-> The "/" character is a separator between writeRoles and readRoles per Security domain and is required even if only one type of role is to be used. The Cisco AVpair string is case sensitive. Although a fault may not be seen, using mismatching cases for the domain name or roles could lead to unexpected privileges being given. ---------------------------------------