For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

Morten_Auguste1's avatar
Morten_Auguste1
Icon for Nimbostratus rankNimbostratus
Jan 17, 2017

Using BIG-IQ and rolebased permissions on objects

Hi If you are using the BIG-IQ Role "Pool Member Operator" for operators to perform pool member operations, you are required to assign the role to all the relvant pools. If you create a new pool - you have to assign the role to that pool. This works fine in small scale. But lets say you have tens or hundreds of pools in the ADC and want to start using this role based access. First thing is the tedious process of clicking through all the pools to assign the role. Then what if the management of BIG-IQ and ADC's are separated and new pools are created - for which you need to assign permissions. How do you find these pools? What if you by mistake forgot to assign permissions for a single pool. How do you check that all pools are assigned the correct role? You can click through all of them - but that's not very useful.

 

I don't see that you can do this in the GUI, or? How is the configuration on BIG-IQ stored? In a database or files? (I haven't found it). (As a workaround you can maybe find the information by searching the config-files)

 

A number of useful GUI enhancements: Posibility of assigning default roles to objects. An easier ways of validating/viewing permissions for all the objects - not having to go into each and every object.

 

BR, M

 

No RepliesBe the first to reply