XOS restrict CLI commands
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Get Direct Link
- Report Inappropriate Content
‎11-27-2015 11:22 AM
Is it possible to restrict the commands for an specific user on the XOS shell ?
For example that this user can only execute "disable inlinepower ..." on ethernet ports ?
PS: i know that via SNMP (tree view) it would be possible also. But we prefer CLI.
Thanks for helpful suggestions.
For example that this user can only execute "disable inlinepower ..." on ethernet ports ?
PS: i know that via SNMP (tree view) it would be possible also. But we prefer CLI.
Thanks for helpful suggestions.
7 REPLIES 7
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Get Direct Link
- Report Inappropriate Content
‎11-30-2015 01:00 PM
We're using Shrubbery's tac_plus (http://www.shrubbery.net/tac_plus/) TACACS+ implementation on a linux box to do authentication (against our AD domain via ldap) , command logging, and access restrictions. Just in case that the "no choice" boils down to "feeding money to Cisco"
Tacacs works with all the 15.5.* firmware versions that we have.
Sorry, it's been a while since I touched anything Radius - I'm not sure where to grab a free/GPL/etc implementation anymore
Tacacs works with all the 15.5.* firmware versions that we have.
Sorry, it's been a while since I touched anything Radius - I'm not sure where to grab a free/GPL/etc implementation anymore
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Get Direct Link
- Report Inappropriate Content
‎11-30-2015 06:11 AM
OK - Cisco ACS (incl. TACACs) is no choice for me ... It seems it is with XOS CLI not possible. So snmp with restricted SNMP views is the only way to get it.
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Get Direct Link
- Report Inappropriate Content
‎11-30-2015 06:05 AM
Matthias!
I don't really remember - it's was a lot time ago, but I remember that as server used Cisco's TACACS server (ACS). ACS have configuration for accepted for use commands:
Thank you!
I don't really remember - it's was a lot time ago, but I remember that as server used Cisco's TACACS server (ACS). ACS have configuration for accepted for use commands:
Thank you!
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Get Direct Link
- Report Inappropriate Content
‎11-30-2015 05:41 AM
Hi Alexandr,
can you give me an example how i can implement this ?
But why only in older versions then XOS 15.2 ? We using X450-G2 with XOS 16.1.1.4.
Regards
can you give me an example how i can implement this ?
But why only in older versions then XOS 15.2 ? We using X450-G2 with XOS 16.1.1.4.
Regards
