Cli; User Roles - Cisco 4215 - Intrusion Detection Sys Sensor Configuration Manual

Configuration guide
Hide thumbs Also See for 4215 - Intrusion Detection Sys Sensor:
Table of Contents

Advertisement

CLI

CLI
The CLI provides the sensor user interface for all direct node access such as Telnet, SSH, and serial
interface. You configure the sensor applications with the CLI. Direct access to the underlying OS is
allowed through the service role.
This section contains the following topics:

User Roles

The CLI for IPS 5.0 permits multiple users to log in at a time. You can create and remove users from the
local sensor. You can only modify one user account at a time. Each user is associated with a role that
controls what that user can and cannot modify
The CLI supports four user roles: Administrator, Operator, Viewer, and Service. The privilege levels for
each role are different; therefore, the menus and available commands vary for each role.
Tip
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 5.0
A-28
User Roles, page A-28
Service Account, page A-29
CLI Behavior, page A-30
Administrators—This user role has the highest level of privileges. Administrators have
unrestricted view access and can perform the following functions:
Add users and assign passwords
Enable and disable control of physical interfaces and virtual sensors
Assign physical sensing interfaces to a virtual sensor
Modify the list of hosts allowed to connect to the sensor as a configuring or viewing agent
Modify sensor address configuration
Tune signatures
Assign configuration to a virtual sensor
Manage routers
Operators—This user role has the second highest level of privileges. Operators have unrestricted
view access and can perform the following functions:
Modify their passwords
Tune signatures
Manage routers
Assign configuration to a virtual sensor
Viewers—This user role has the lowest level of privileges. Viewers can view configuration and
event data and can modify their passwords.
Monitoring applications only require viewer access to the sensor. You can use the CLI to set up
a user account with viewer privileges and then configure the event viewer to use this account to
connect to the sensor.
Appendix A
System Architecture
78-16527-01

Advertisement

Table of Contents
loading

Table of Contents