On Tue, 2009-07-14 at 18:05 +0200, Gert Doering wrote:
> Mmmmh.  If one does TACACS command authentication, one could
> investigate whether disallowing the "without-add/-delete" form of the
> command via TACACS works...

It does indeed. We use something similar to the configuration below for
"operators" who can do simple maintenance chores.

group = operator {
        default service = deny
        login = PAM
        service = exec {
                priv-lvl = 15
        }
        ...
        cmd = switchport {
                permit "^trunk allowed vlan add 1[0-9][0-9] <cr>$"
                permit "^trunk allowed vlan remove 1[0-9][0-9] <cr>$"
                ...
        }
        ...
}

Regards,
Peter


_______________________________________________
cisco-nsp mailing list  [email protected]
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/

Reply via email to