For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

gpayne_144568's avatar
gpayne_144568
Icon for Nimbostratus rankNimbostratus
Apr 07, 2014

Administrative Partitions

I have a client that wants to co-manage the F5. Their intent is to be able to add/remove VIPS, Pools, Members Irules and monitors.

 

The question that I have is this, is there a way that this partition can be done to ensure that there is nothing that the client can do as a co-manager to the F5 that would affect the other clients on the device.

 

The client has suggested a container type access, but I think that if they were to create a script and or Irule that pointed to something outside their partition and it was wrong it would affect the whole network.

 

Need some advice, Thank you

 

3 Replies

  • Jana's avatar
    Jana
    Icon for Altostratus rankAltostratus

    Following are a few links about partitions on the bigip. Gives details about the object access across partitions.

     

    http://support.f5.com/kb/en-us/products/big-ip_ltm/manuals/product/tmos-concepts-11-4-0/8.html

     

    http://support.f5.com/kb/en-us/products/big-ip_ltm/manuals/product/tmos-concepts-11-2-0/tmos_partitions_and_folders.html

     

  • JG's avatar
    JG
    Icon for Cumulonimbus rankCumulonimbus

    I would avoid giving admin rights to people who do not really understand how these devices work. A rogue "para-admin" could do things that will ruin the performance of the whole box easily. Also there is no locking to prevent administrative tasks from being carried out simultaneously. And just think how you can manage backing up of the conf in such a situation and know what has changed?

     

  • Partitions are also a pain to deal with in general. If the client wants to manage the F5 get them a VE edition and give them access.