Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
LostBoY
Advisor

Checkfailover with Readonly User

I am trying to integrate my R80.40 GWs with Cisco ISE.. i am facing problem with Read Only Privilige. i would like read only users to monitor failover status but they cant run show cluster state with monitorOnly Role

 

how can i get this to work with RO users

0 Kudos
6 Replies
_Val_
Admin
Admin

you can create a new role based on MonitorOnly and add additional commands you want those users to run

LostBoY
Advisor

is it possible to clone monitorOnly and add additonal features ? i was looking at monitorOnly rba role and it mentions access to cluster info but when i run it i get an error /bin/cphaprob_start line 6 permission denied

0 Kudos
_Val_
Admin
Admin

Role management is described in the Gaia Admin guide. You can create custom roles with certain additional commands for your needs

0 Kudos
LostBoY
Advisor

Thanks.. i got certain things to work here.. created a role and added few view commands to it such as ntp, configuration, dns , aaa servers. However , 2 things i cudnt work out.

1) Virtual system access 

2) show cluster state in this custom monitor role

regarding virtual system access i am able to run set virtual-system 2 .. but post that i cannot run any command it keeps throwing this error : supsh0361 failure setting current vrf id

as for the > show cluster state i get this error : /bin/cphaprob_start line 6 permission denied

if i can somehow get these things to work it will be very helpful.

0 Kudos
_Val_
Admin
Admin

Check default shell for that account. Some commands will not work from clish and require bash

 

0 Kudos
LostBoY
Advisor

But from adminRole users i can run show cluster state fron GAIA shell itself.. however its not working with custom roles

0 Kudos