cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
638
Views
0
Helpful
1
Replies

ACE module RBAC

Sergey Fuklev
Level 1
Level 1

Good day.

I have a question about RBAC on Cisco ACE.

Is it a possible create user role, whitch allowed monitor serverfarm state ("show serverfarm xxx" {detail} command), but restrict "show running/startup config" commands?

Configuration like following did not work (show commands not available):

role tst

    rule 1 permit monitor feature serverfarm

    rule 2 deny monitor

However Virtual Configuration Guide said ''The rule number determines the order in which the ACE applies the rules, with a higher-numbered rule applied after a lower-numbered rule''.

So it is possible to accomplished?

1 Reply 1

chrhiggi
Level 3
Level 3

Hello Anatoliy-

  Show run is permitted for all roles,/features, there is no way to disable it.

Regards,

  Chris Higgins