Cisco Explorer 4700 Installationsanleitung Seite 574

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 648
  • Inhaltsverzeichnis
  • FEHLERBEHEBUNG
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 573
15-6
Device Manager Guide, Cisco ACE 4700 Series Application Control Engine Appliance
OL-26645-02
Chapter 15 Managing the ACE Appliance
Controlling Access to the Cisco ACE Appliance
Note If you need to restrict a users access, you must assign a role-domain pair. Otherwise, no matter
what roles the user may have, that user will not be able to access any specific resources, and,
therefore, will have no powers on the system.
All users are strictly limited by the combination of their contexts, roles, and domains. For example, a
user cannot create another user who has greater privileges or access or is outside their domain.
Roles cannot be deleted if they are currently referenced by a user. The predefined roles cannot be
changed or deleted.
Related Topics
Guidelines for Managing User Roles, page 15-14
Role Mapping in ACE Appliance Device Manager, page 15-19
Displaying User Roles, page 15-28
Creating User Roles, page 15-28
Modifying User Roles, page 15-30
Deleting User Roles, page 15-30
Understanding Operations Privileges
Operations privileges define what users can do in the designated context. There are two levels of access.
The first level is the permit or deny permission. The second level is the operations privilege the user is
permitted or denied from performing. For example, each feature on the ACE appliance has an assigned
privilege. If a users privileges are not sufficient, the feature will not be available to them. The following
operations privileges can be permitted or denied from least to greatest privilege levels:
Monitor—Allows the user to view statistics and specify parameter collection.
Modify—Allows the user to change the persistent information associated with system objects, such
as a configuration.
Debug—Allows the user to collect information on existing problems.
Create—Allows the user to control system objects, for example, creating them, enabling them, or
powering up; also has delete permission.
Privileges are hierarchical. If a user has Modify privileges, they have Monitor privileges as well. If a
user has Create or Debug privileges, they have Modify privileges as well. Only Admin has Resource
Class Mgmt access.
Note The ability to create automatically contains the modify function, but the reverse is not true (a user with
modify privileges cannot automatically create items).
Related Topics
Guidelines for Managing User Roles, page 15-14
Role Mapping in ACE Appliance Device Manager, page 15-19
Managing User Roles, page 15-14
Seitenansicht 573
1 2 ... 569 570 571 572 573 574 575 576 577 578 579 ... 647 648

Kommentare zu diesen Handbüchern

Keine Kommentare