<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic XOS restrict CLI commands in ExtremeSwitching (EXOS/Switch Engine)</title>
    <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/xos-restrict-cli-commands/m-p/30473#M5196</link>
    <description>Is it possible to restrict the commands for an specific user on the XOS shell ?&lt;BR /&gt;
For example that this user can only execute "disable inlinepower ..." on ethernet ports ?&lt;BR /&gt;
&lt;BR /&gt;
PS: i know that via SNMP (tree view) it would be possible also. But we prefer CLI. &lt;BR /&gt;
&lt;BR /&gt;
Thanks for helpful suggestions.&lt;BR /&gt;</description>
    <pubDate>Fri, 27 Nov 2015 19:22:00 GMT</pubDate>
    <dc:creator>M_Nees</dc:creator>
    <dc:date>2015-11-27T19:22:00Z</dc:date>
    <item>
      <title>XOS restrict CLI commands</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/xos-restrict-cli-commands/m-p/30473#M5196</link>
      <description>Is it possible to restrict the commands for an specific user on the XOS shell ?&lt;BR /&gt;
For example that this user can only execute "disable inlinepower ..." on ethernet ports ?&lt;BR /&gt;
&lt;BR /&gt;
PS: i know that via SNMP (tree view) it would be possible also. But we prefer CLI. &lt;BR /&gt;
&lt;BR /&gt;
Thanks for helpful suggestions.&lt;BR /&gt;</description>
      <pubDate>Fri, 27 Nov 2015 19:22:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/xos-restrict-cli-commands/m-p/30473#M5196</guid>
      <dc:creator>M_Nees</dc:creator>
      <dc:date>2015-11-27T19:22:00Z</dc:date>
    </item>
    <item>
      <title>RE: XOS restrict CLI commands</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/xos-restrict-cli-commands/m-p/30474#M5197</link>
      <description>Not yet.&lt;BR /&gt;</description>
      <pubDate>Mon, 30 Nov 2015 01:31:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/xos-restrict-cli-commands/m-p/30474#M5197</guid>
      <dc:creator>Sumit_Tokle</dc:creator>
      <dc:date>2015-11-30T01:31:00Z</dc:date>
    </item>
    <item>
      <title>RE: XOS restrict CLI commands</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/xos-restrict-cli-commands/m-p/30475#M5198</link>
      <description>Hi Matthias,&lt;BR /&gt;
      I checked in  documentation and tried in lab as well to see if this functionality exists, I do not see any such functionality supported till EXOS 16.1.  User accounts can be only be &lt;BR /&gt;
1. Admin - With Read and write access&lt;BR /&gt;
2. User - With Read only access&lt;BR /&gt;
&lt;BR /&gt;
Do you want your requirement to be supported in later version of EXOS?&lt;BR /&gt;
&lt;BR /&gt;
If yes, please open a service request with GTAC for feature request.&lt;BR /&gt;
&lt;BR /&gt;
Thanks,Syed&lt;BR /&gt;</description>
      <pubDate>Mon, 30 Nov 2015 12:06:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/xos-restrict-cli-commands/m-p/30475#M5198</guid>
      <dc:creator>Rahmathullah__S</dc:creator>
      <dc:date>2015-11-30T12:06:00Z</dc:date>
    </item>
    <item>
      <title>RE: XOS restrict CLI commands</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/xos-restrict-cli-commands/m-p/30476#M5199</link>
      <description>Hi, Matthias!&lt;BR /&gt;
&lt;BR /&gt;
You can do this when you use RADIUS server for authentication.&lt;BR /&gt;
In RADIUS server configuration you can type commands which accept for use certain users.&lt;BR /&gt;
&lt;BR /&gt;
But this was in EXOS less then 15.2 version.&lt;BR /&gt;
&lt;BR /&gt;
Thank you!</description>
      <pubDate>Mon, 30 Nov 2015 13:35:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/xos-restrict-cli-commands/m-p/30476#M5199</guid>
      <dc:creator>Alexandr_P</dc:creator>
      <dc:date>2015-11-30T13:35:00Z</dc:date>
    </item>
    <item>
      <title>RE: XOS restrict CLI commands</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/xos-restrict-cli-commands/m-p/30477#M5200</link>
      <description>Hi Alexandr,&lt;BR /&gt;
&lt;BR /&gt;
can you give me an example how i can implement this ? &lt;BR /&gt;
But why only in older versions then XOS 15.2 ? We using X450-G2 with XOS 16.1.1.4.&lt;BR /&gt;
&lt;BR /&gt;
Regards&lt;BR /&gt;</description>
      <pubDate>Mon, 30 Nov 2015 13:41:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/xos-restrict-cli-commands/m-p/30477#M5200</guid>
      <dc:creator>M_Nees</dc:creator>
      <dc:date>2015-11-30T13:41:00Z</dc:date>
    </item>
    <item>
      <title>RE: XOS restrict CLI commands</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/xos-restrict-cli-commands/m-p/30478#M5201</link>
      <description>Matthias!&lt;BR /&gt;
&lt;BR /&gt;
I don't really remember - it's was a lot time ago, but I remember that as server used Cisco's TACACS server (ACS). ACS have configuration for accepted for use commands:&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="29fba55f3e91475089e376d665455ef2_RackMultipart20151130-11716-wwrfl0-1_inline.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/1522i1BAECF0D9E0754E7/image-size/large?v=v2&amp;amp;px=999" role="button" title="29fba55f3e91475089e376d665455ef2_RackMultipart20151130-11716-wwrfl0-1_inline.png" alt="29fba55f3e91475089e376d665455ef2_RackMultipart20151130-11716-wwrfl0-1_inline.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="29fba55f3e91475089e376d665455ef2_RackMultipart20151130-6510-1fm50td-2_inline.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/1081iC7D0DD33596303D2/image-size/large?v=v2&amp;amp;px=999" role="button" title="29fba55f3e91475089e376d665455ef2_RackMultipart20151130-6510-1fm50td-2_inline.png" alt="29fba55f3e91475089e376d665455ef2_RackMultipart20151130-6510-1fm50td-2_inline.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="29fba55f3e91475089e376d665455ef2_RackMultipart20151130-6762-1palxbw-3_inline.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/5015i9E1F16683D2179A7/image-size/large?v=v2&amp;amp;px=999" role="button" title="29fba55f3e91475089e376d665455ef2_RackMultipart20151130-6762-1palxbw-3_inline.png" alt="29fba55f3e91475089e376d665455ef2_RackMultipart20151130-6762-1palxbw-3_inline.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="29fba55f3e91475089e376d665455ef2_RackMultipart20151130-18020-87qvfh-4_inline.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/884i0A36D9A9C5C1419F/image-size/large?v=v2&amp;amp;px=999" role="button" title="29fba55f3e91475089e376d665455ef2_RackMultipart20151130-18020-87qvfh-4_inline.png" alt="29fba55f3e91475089e376d665455ef2_RackMultipart20151130-18020-87qvfh-4_inline.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;BR /&gt;
Thank you!</description>
      <pubDate>Mon, 30 Nov 2015 14:05:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/xos-restrict-cli-commands/m-p/30478#M5201</guid>
      <dc:creator>Alexandr_P</dc:creator>
      <dc:date>2015-11-30T14:05:00Z</dc:date>
    </item>
    <item>
      <title>RE: XOS restrict CLI commands</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/xos-restrict-cli-commands/m-p/30479#M5202</link>
      <description>OK - Cisco ACS (incl. TACACs) is no choice for me ... It seems it is with XOS CLI not possible. So snmp with restricted SNMP views is the only way to get it.&lt;BR /&gt;</description>
      <pubDate>Mon, 30 Nov 2015 14:11:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/xos-restrict-cli-commands/m-p/30479#M5202</guid>
      <dc:creator>M_Nees</dc:creator>
      <dc:date>2015-11-30T14:11:00Z</dc:date>
    </item>
    <item>
      <title>RE: XOS restrict CLI commands</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/xos-restrict-cli-commands/m-p/30480#M5203</link>
      <description>We're using Shrubbery's tac_plus (&lt;A href="http://www.shrubbery.net/tac_plus/" target="_blank" rel="nofollow noreferrer noopener"&gt;http://www.shrubbery.net/tac_plus/&lt;/A&gt;) TACACS+ implementation on a linux box to do authentication (against our AD domain via ldap) , command logging, and access restrictions. Just in case that the "no choice" boils down to "feeding money to Cisco"&lt;BR /&gt;
Tacacs works with all the 15.5.* firmware versions that we have.&lt;BR /&gt;
&lt;BR /&gt;
Sorry, it's been a while since I touched anything Radius - I'm not sure where to grab a free/GPL/etc implementation anymore&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Mon, 30 Nov 2015 21:00:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/xos-restrict-cli-commands/m-p/30480#M5203</guid>
      <dc:creator>Frank</dc:creator>
      <dc:date>2015-11-30T21:00:00Z</dc:date>
    </item>
  </channel>
</rss>

