Start a Conversation

Unsolved

This post is more than 5 years old

GS

974

October 29th, 2012 23:00

What Cisco user permissions are required for ECC to discover a switch?

When discovering Cisco switches running firmware versions earlier than 5.2.1, I was able to use a user account that was part of the network-operator group.  Even though ControlCenter warned that the account did not have write privileges, it was not an issue since I used ControlCenter mainly for monitoring and reporting -- not to make any changes.  However, for switches running version 5.2.x, this no longer works because Cisco apparently changed the underlying permissions for the network-operator group (see Primus article emc292977: After upgrade to NX-OS 5.2.x network-operator role cannot execute show run or show start commands.)  In the Primus article, they provide an example of creating a new role that allows access to the show running-config and show startup-config that should have provided the same permissions as the older network-operator group.  Note that the commands described in the article are not correct since NX-OS 5.2.x requires the use of the keyword feature after "permit " and some of the features like the copy command cannot be restricted to a specific source.  In my case, I added all the roles from the Primus article with the exception of the "permit exec copy" command since I did not think that would be necessary for discovery.  ControlCenter still failed to connect to the switch even with a new user created as a member of this group.  I tried this with different user accounts and verified that using an administrative account allowed the switch to be discovered.  So my question is, does anyone know what specific permissions ControlCenter needs on the Cisco switches in order to perform a read-only discovery of the switch?  Or is there a document which lists the specific permissions required?

472 Posts

October 30th, 2012 01:00

Hi,

The ControlCenter Planning & Installation Guide, Volume 1 states that network-operator permissions should only be required if you only plan to discover the Cisco switches for monitoring and reporting (no active management):

If ControlCenter is to be used for alerting and reporting only, all Cisco switches in
the fabric may be configured with a user that has network-operator or read only

privileges. Of course, they may have network-administrator permissions, if so

desired.

Now it is possible that the more recent Cisco firmware will only allow a ControlCenter discovery to succeed with the network-administrator role and therefore the documentation may need to be updated accordingly.

Regards,

Séamus Coffey

EMC Customer Support Services


No Events found!

Top