Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
Hello,I'm creating this new discussion because I'm trying to have some clarifications about the built-in trustpool in network devices.I found a lot of valuable information in https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_conn_pki/configuratio...
I was able to block the command runner with a proxy denying "^/api/v1/network-device-poller/cli/read-request"Hope it helps you work around your problem too.
This command runner line in RBAC is a must for security reasons.I would even say, what is really needed is an advanced RBAC that would be as granular as possible.