On Tue, 2009-07-14 at 18:05 +0200, Gert Doering wrote:
> Mmmmh. If one does TACACS command authentication, one could
> investigate whether disallowing the "without-add/-delete" form of the
> command via TACACS works...
It does indeed. We use something similar to the configuration below for
"operators" who can do simple maintenance chores.
group = operator {
default service = deny
login = PAM
service = exec {
priv-lvl = 15
}
...
cmd = switchport {
permit "^trunk allowed vlan add 1[0-9][0-9] <cr>$"
permit "^trunk allowed vlan remove 1[0-9][0-9] <cr>$"
...
}
...
}
Regards,
Peter
_______________________________________________
cisco-nsp mailing list [email protected]
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/