<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic XMC - User Group with only read-only access to some devices in ExtremeCloud IQ- Site Engine Management Center</title>
    <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/xmc-user-group-with-only-read-only-access-to-some-devices/m-p/91252#M9582</link>
    <description>Hi,&lt;BR /&gt;
&lt;BR /&gt;
i'm actually designing user right to device in xmc 8.2.&lt;BR /&gt;
&lt;BR /&gt;
For the example, the user "DIT" should be able to have full right on certain devices and only read-only right to certain other device.&lt;BR /&gt;
&lt;BR /&gt;
I created a local user "DIT" in a specific user-group "DIT_LILLE" with standard netsight right (allow set snmp to devices is checked)&lt;BR /&gt;
&lt;BR /&gt;
I created 2 profiles :&lt;BR /&gt;
&lt;UL&gt; 
&lt;LI&gt;the first profile (RW) have Read-write CLI and Read-write SNMP credentials (SNMPv3) 
&lt;/LI&gt;&lt;LI&gt;the second profile (RO) have read-only CLI and read-only SNMP credentials (SNMPv3) 
&lt;/LI&gt;&lt;/UL&gt;
I mapped the RW profile to a device "sw-bur30" and the RO profile to a second device "SW-alsit" for the user group "DIT_LILLE" in the device-mapping.&lt;BR /&gt;
&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="72174e2296c8419ebb1c037b01f79eb2_1b737046-cd7b-4123-acf4-1b9491989ad8.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/183i8CE1844F2FFD152E/image-size/large?v=v2&amp;amp;px=999" role="button" title="72174e2296c8419ebb1c037b01f79eb2_1b737046-cd7b-4123-acf4-1b9491989ad8.png" alt="72174e2296c8419ebb1c037b01f79eb2_1b737046-cd7b-4123-acf4-1b9491989ad8.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;BR /&gt;
&lt;BR /&gt;
Both of the device have a default administration profile set to the RW profile.&lt;BR /&gt;
&lt;BR /&gt;
When I log on with the "DIT" user, I can make change to interface status and i can enforce device configuration on both device so the RO profile seems to not being used ...&lt;BR /&gt;
&lt;BR /&gt;
If I uncheck the ''allow set snmp to device'', the user is unable to make change to both devices.&lt;BR /&gt;
&lt;BR /&gt;
So it seems that the user "DIT" is using the administration profile set globally to the devices instead of the specific one made in the device-mapping .&lt;BR /&gt;
&lt;BR /&gt;
here is the SNMPv3 user configuration on the device:&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="72174e2296c8419ebb1c037b01f79eb2_9a2ed35f-02a2-475d-9c68-5d55456f6f88.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/5590i3E70E06CAE37C649/image-size/large?v=v2&amp;amp;px=999" role="button" title="72174e2296c8419ebb1c037b01f79eb2_9a2ed35f-02a2-475d-9c68-5d55456f6f88.png" alt="72174e2296c8419ebb1c037b01f79eb2_9a2ed35f-02a2-475d-9c68-5d55456f6f88.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;BR /&gt;
I made a tcpdump of a disable port sent to the read-only device and I can see that XMC didn't use the specific SNMPv3 user xmc_ro but the RW one xmc.&lt;BR /&gt;
&lt;BR /&gt;
16:22:35.659049 IP pns1scmgb001.prod-exp.justice.fr.39111 &amp;gt; 10.79.252.245.snmp: F=apr U="xmc" [!scoped PDU]83_54_9e_aa_11_f9_05_7d_8d_84_20_77_f0_f8_32_27_10_a8_f4_e5_a4_aa_71_e3_25_0c_49_a9_2c_33_c1_fa_89_c8_1a_ba_33_ac_01_f6_b3_62_38_e6_8e_d8_84_13_b1_c7_c7_f9_c1_64_fa_e6_01_50_16&lt;BR /&gt;
16:22:35.671323 IP 10.79.252.245.snmp &amp;gt; pns1scmgb001.prod-exp.justice.fr.39111: F=ap U="xmc" [!scoped PDU]92_e9_b2_94_6f_89_f9_87_2f_cb_f8_ab_0a_f9_f9_92_f3_7e_38_be_3e_3e_04_39_2d_5e_c7_4a_d2_96_fe_cc_0c_49_ba_e9_2e_cc_54_b5_9f_05_c4_1b_da_12_26_48_08_18_1f_f7_12_13_af_ef_53_a9_f0&lt;BR /&gt;
&lt;BR /&gt;
Is there someone here that managed to deal with this ?&lt;BR /&gt;
&lt;BR /&gt;
thanks!</description>
    <pubDate>Tue, 12 Mar 2019 21:45:06 GMT</pubDate>
    <dc:creator>Sbinet</dc:creator>
    <dc:date>2019-03-12T21:45:06Z</dc:date>
    <item>
      <title>XMC - User Group with only read-only access to some devices</title>
      <link>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/xmc-user-group-with-only-read-only-access-to-some-devices/m-p/91252#M9582</link>
      <description>Hi,&lt;BR /&gt;
&lt;BR /&gt;
i'm actually designing user right to device in xmc 8.2.&lt;BR /&gt;
&lt;BR /&gt;
For the example, the user "DIT" should be able to have full right on certain devices and only read-only right to certain other device.&lt;BR /&gt;
&lt;BR /&gt;
I created a local user "DIT" in a specific user-group "DIT_LILLE" with standard netsight right (allow set snmp to devices is checked)&lt;BR /&gt;
&lt;BR /&gt;
I created 2 profiles :&lt;BR /&gt;
&lt;UL&gt; 
&lt;LI&gt;the first profile (RW) have Read-write CLI and Read-write SNMP credentials (SNMPv3) 
&lt;/LI&gt;&lt;LI&gt;the second profile (RO) have read-only CLI and read-only SNMP credentials (SNMPv3) 
&lt;/LI&gt;&lt;/UL&gt;
I mapped the RW profile to a device "sw-bur30" and the RO profile to a second device "SW-alsit" for the user group "DIT_LILLE" in the device-mapping.&lt;BR /&gt;
&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="72174e2296c8419ebb1c037b01f79eb2_1b737046-cd7b-4123-acf4-1b9491989ad8.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/183i8CE1844F2FFD152E/image-size/large?v=v2&amp;amp;px=999" role="button" title="72174e2296c8419ebb1c037b01f79eb2_1b737046-cd7b-4123-acf4-1b9491989ad8.png" alt="72174e2296c8419ebb1c037b01f79eb2_1b737046-cd7b-4123-acf4-1b9491989ad8.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;BR /&gt;
&lt;BR /&gt;
Both of the device have a default administration profile set to the RW profile.&lt;BR /&gt;
&lt;BR /&gt;
When I log on with the "DIT" user, I can make change to interface status and i can enforce device configuration on both device so the RO profile seems to not being used ...&lt;BR /&gt;
&lt;BR /&gt;
If I uncheck the ''allow set snmp to device'', the user is unable to make change to both devices.&lt;BR /&gt;
&lt;BR /&gt;
So it seems that the user "DIT" is using the administration profile set globally to the devices instead of the specific one made in the device-mapping .&lt;BR /&gt;
&lt;BR /&gt;
here is the SNMPv3 user configuration on the device:&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="72174e2296c8419ebb1c037b01f79eb2_9a2ed35f-02a2-475d-9c68-5d55456f6f88.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/5590i3E70E06CAE37C649/image-size/large?v=v2&amp;amp;px=999" role="button" title="72174e2296c8419ebb1c037b01f79eb2_9a2ed35f-02a2-475d-9c68-5d55456f6f88.png" alt="72174e2296c8419ebb1c037b01f79eb2_9a2ed35f-02a2-475d-9c68-5d55456f6f88.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;BR /&gt;
I made a tcpdump of a disable port sent to the read-only device and I can see that XMC didn't use the specific SNMPv3 user xmc_ro but the RW one xmc.&lt;BR /&gt;
&lt;BR /&gt;
16:22:35.659049 IP pns1scmgb001.prod-exp.justice.fr.39111 &amp;gt; 10.79.252.245.snmp: F=apr U="xmc" [!scoped PDU]83_54_9e_aa_11_f9_05_7d_8d_84_20_77_f0_f8_32_27_10_a8_f4_e5_a4_aa_71_e3_25_0c_49_a9_2c_33_c1_fa_89_c8_1a_ba_33_ac_01_f6_b3_62_38_e6_8e_d8_84_13_b1_c7_c7_f9_c1_64_fa_e6_01_50_16&lt;BR /&gt;
16:22:35.671323 IP 10.79.252.245.snmp &amp;gt; pns1scmgb001.prod-exp.justice.fr.39111: F=ap U="xmc" [!scoped PDU]92_e9_b2_94_6f_89_f9_87_2f_cb_f8_ab_0a_f9_f9_92_f3_7e_38_be_3e_3e_04_39_2d_5e_c7_4a_d2_96_fe_cc_0c_49_ba_e9_2e_cc_54_b5_9f_05_c4_1b_da_12_26_48_08_18_1f_f7_12_13_af_ef_53_a9_f0&lt;BR /&gt;
&lt;BR /&gt;
Is there someone here that managed to deal with this ?&lt;BR /&gt;
&lt;BR /&gt;
thanks!</description>
      <pubDate>Tue, 12 Mar 2019 21:45:06 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremecloud-iq-site-engine/xmc-user-group-with-only-read-only-access-to-some-devices/m-p/91252#M9582</guid>
      <dc:creator>Sbinet</dc:creator>
      <dc:date>2019-03-12T21:45:06Z</dc:date>
    </item>
  </channel>
</rss>

