Reply
Greenback fjo
Greenback
fjo
Posts: 29
Registered: 06-10-2010
0

Re: Role based account / admin privileges

Hi,

 

sorry for my late reply. They are running 6.5.1a, but I have encountered this on a virtual SH 6.5.0, too.

 

Felix

Administrator
cgeary
Posts: 938
Registered: 06-28-2010
0

Re: Role based account / admin privileges

This is currently expected behaviour. We have an RFE open (51424) to permit this but I cannot confirm when or if that may make it into a future release.

--------------------------------------------
Chris Geary - Riverbed Support
--------------------------------------------
If this answered your question, please click "Accept as Solution" ------->
Administrator
cgeary
Posts: 938
Registered: 06-28-2010
0

Re: Role based account / admin privileges

I've reproduced the behaviour on 6.1.2a. Which version are you using? A quick search internally hasn't revealed any existing bugs reported around this area so I filed a new one to verify if this is expected behaviour for any reason. I'm afraid I can't offer a suitable workaround for this, other than using RADIUS/TACACS which I know does work when a user is mapped to the admin role.

--------------------------------------------
Chris Geary - Riverbed Support
--------------------------------------------
If this answered your question, please click "Accept as Solution" ------->
Greenback fjo
Greenback
fjo
Posts: 29
Registered: 06-10-2010
0

Re: Role based account / admin privileges

I'm afraid they don't want to use RADIUS although our Windows guys offered them to setup a Radius server on Windows 2008 which is their prefered OS.

 

Felix

Administrator
cgeary
Posts: 938
Registered: 06-28-2010
0

Re: Role based account / admin privileges

Do they definitely not want a centralised RADIUS/TACACS based authentication solution? That would be simpler. You can then map multiple users/groups to the admin role.

--------------------------------------------
Chris Geary - Riverbed Support
--------------------------------------------
If this answered your question, please click "Accept as Solution" ------->
Greenback fjo
Greenback
fjo
Posts: 29
Registered: 06-10-2010
0

Re: Role based account / admin privileges

Thought so, too. I configured a rbm user with read/write permission but that user cannot view the current config:

 

Running Configuration
Insufficient permissions for command execution.



Although the user is allowed to activate another config. I can reproduce that on SH 6.5.1a and CMC 6.5.0. Our goal is to have multiple admin users with different names.

 

Felix

Administrator
cgeary
Posts: 938
Registered: 06-28-2010
0

Re: Role based account / admin privileges

Sure. Go to Configure › Security › User Permissions. Then add a new user in Role Based Accounts and 'Select all' for read/write. Do you just want to be able to view the current config or fully administer the appliance?

--------------------------------------------
Chris Geary - Riverbed Support
--------------------------------------------
If this answered your question, please click "Accept as Solution" ------->
Greenback fjo
Greenback
fjo
Posts: 29
Registered: 06-10-2010
0

Role based account / admin privileges

Hi,

 

maybe a dumb question, but is there any possibility to grant a role base (read: local) account admin privileges, eg. to view the current configuration? A customer doesn't like my (Free)Radius solution and wants to stay with local user accounts. This is probably a feature request..

 

Thanks,

Felix

‬‪‬‪‬‪