Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations gkittelson on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Need to grant Read-Only access to configurations but none to devices

Status
Not open for further replies.

jj752

Technical User
Jun 18, 2003
1
US
I need to grant access to our router and switch configurations to an IT Auditor in our company. However, the current roles limit my choices to either Network Operator or Network Admin. Obviously, these two roles are far too powerful to grant to our auditor since he would also have the ability to mess with our devices. Is there a way to grant him the access to the configurations WITHOUT giving him access to our devices?
 
We have looked for a similar functionality in the past; however, unfortunately we have never found a way to do this. We have requested increased functionality from Cisco, but to date, they have not committed to increasing the flexibility with the roles and responsibilities. If you find something, I would love to hear about it.

Todd Hethmon
thethmon@hethmon.com
 
Have you thought about using Cisco ACS for AAA? You can have the auditor login and authenticate to a tacacs server and only allow them to run commands that you specify.
 
There is a software application, I have seen that should give the flexibility, you require.
The other method would be to copy the configs from the archive/shadow subdirectories to where they can be accessed by the auditor.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top