Forum Discussion
Luis_54441
Nimbostratus
Aug 01, 2008Restricting user access rights to the BIGIP
Hi,
I am looking for a way to let a customer have SSH access so that he can:
+ see bigtop staticstics
+ view logs
+ run TCPDUMP & SSLDUMP
+ but, DO NOT want him to have access to configuration utilities like bigpipe commands
I have read that for any type of account (Guest, Operator, Application Editor, Application Security Policy Editor, Manager, User Manager, Resource Administrator, Administrator ) you have threepossible terminal access:
- disabled: no ssh access
- Advanced Shell: access to the unix bash shell.
- bigpipe shell: access to F5's shell.
But I do not understand if i have to enable the bigpipe shell to get the bigtop commands, and the TCPDUMP & SSLDUMP utilities. I also have not very clear if i select a guest role (no write permissions at all) but i give that guest SSH access to the bigpipe shell, will that user be able to change the BIGIP configuration using bigpipe commands?
I will really appreciate any information regarding this issue.
Thanks very much
- Hamish
Cirrocumulus
What version of BigIP are you running? - Luis_54441
Nimbostratus
V9.1.3. - Hamish_Marson_3
Nimbostratus
In v4.x you could create an ordinary CLI user with a custom UID and then use sudo to allow access to certain commands. In v9.x this was removed. Now all CLI users have to have UID=0 (When I say have to, F5's response was that only UID=0 is supported) and there is now no sudo. - Luis_54441
Nimbostratus
Thanks very much, - JRahm
Admin
tcpdump is available in the web interface 9n 9.4, but I don't believe ssldump is.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects