Forum Discussion
Role to delegate APM administration
Hi, we've implemented Kerberos authentication using APM, but now that is all up and running we'd like to delegate the administration of the Visual Policy Editor and all the APM related objects (Kerberos AAA, Active Directory AAA...) to the security folks. I know that there's a "Application Security Policy Editor" role that seems to apply only to ASM. I'd need something like the "APM administrator role". Is there something like that? can I somehow delegate the APM administration?
I'm afraid that maybe I can't delegate it, so I've thought in create a separate guest in my vCMP system so I can license the APM on that new guest. In that way I'd have my LTM guest and my APM guest, and I could give the administrator account in the APM guest to the security folks without need to handle with the "user roles" problem. But I don't know if I can have LTM and APM in different systems, because I've worked only in a system where LTM and APM were licensed together, so I can reference the APM policies from the LTM Virtual Servers as a local object. If I have the APM in a separate guest from the LTM, how I'd reference the policy objects? I have search, with no luck, any deployment guide for a "one LTM with several APM" and I hav found nothing... any references?
Thanks!
4 Replies
- Gianrico
Employee
Why do not you create a partition and put the apm objects in that partition? Then assign APM administrator access to that partition.
Just a thought
- Angel_Lopez_116
Altostratus
I'm not used to work with partitions so that's pretty new as a feature to me. So if I follow you, I could create a new partition (I'm only working with the default Common partition right now) and I could assign every APM object that I create to that partition. But, when you say "APM administrator access"... what do you mean? becasuse the administrator role can't be assigned to a single partition, right?
- Gianrico_D_Ang1Historic F5 AccountI am sorry the answer was confusing. What I meant was: you can assign access to that partition to the apm administrator. I think the role to assign to the apm administrator is the Manager role. gianrico
- Walter_Kacynski
Cirrostratus
The Manager role will work for most APM stuff. However, if you use Hosted Content, this is device wide and a user must be granted the Administrator role.
Depending on your version, anything less than 11.6, the apm logs are easier viewed and queried directly from the shell terminal. So, you admins with have limited troubleshooting capabilities unless you forward your logs to an external server.
Under 11.6, they added the access log to System -> Logs
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com