Cisco Explorer 4700 Installation Guide Page 140

  • Download
  • Add to my manuals
  • Print
  • Page
    / 648
  • Table of contents
  • TROUBLESHOOTING
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews
Page view 139
5-4
Device Manager Guide, Cisco ACE 4700 Series Application Control Engine Appliance
OL-26645-02
Chapter 5 Configuring Virtual Servers
Configuring Virtual Servers
Configuration options and roles
To support and maintain the separation of roles, some objects cannot be configured using the Virtual
Server configuration screen. These objects include SSL certificates, SSL keys, NAT pools, interface
IP addresses, and ACLs. Providing these options as separate configuration options in the ACE
Appliance Device Manager interface ensures that a user who can view or modify virtual servers or
aspects of virtual servers cannot create or delete virtual servers.
RBAC role and domain requirements
If you want to create, modify, or delete a virtual server, we recommend that you use the pre-defined
Admin role (see Table 15-4).Only the Admin pre-defined role supports the ability to successfully
deploy a functional virtual server from the ACE appliance Device Manager.
If a user prefers to be assigned a custom role, and wants the ability to create, modify, or delete a
virtual server, that user requires the proper role permissions to be defined by the administrator to
allow them to perform those virtual server activities.
Note A user must be assigned with a default domain (default-domain) to be able to configure a virtual
server. A domain is the namespace in which a user operates.
Included below are a list of RBAC permissions which are required for a user to create, modify, or
delete a virtual server:
---------------------------------------------
Rule Type Permission Feature
---------------------------------------------
1. Permit Create real
2. Permit Create serverfarm
3. Permit Create vip
4. Permit Create probe
5. Permit Create loadbalance
6. Permit Create nat
7. Permit Create interface
8. Permit Create connection
9. Permit Create ssl
10. Permit Create pki
11. Permit Create sticky
12. Permit Create inspect
Note that certain configured virtual servers may only cover a subset of the features and may not
require all the permissions outlined above. In general, the above set of permissions are required for
allowing users to configure all elements of a virtual server.
For background information, see the “Managing User Roles” section in Chapter 15, “Managing the
ACE Appliance”.
Related Topics
Configuring Virtual Servers, page 5-2
Information About Using Device Manager to Configure Virtual Servers, page 5-5
Virtual Server Configuration Procedure, page 5-7
Page view 139
1 ... 139 140 141 ... 648

Comments to this Manuals

No comments