5-59
User
Guide

for

the

Cisco

Application

Networking

Manager

5.2
OL-26572-01
Chapter
5






Importing

and

Managing

Devices
Configuring
ACE

Module

and

Appliance

Role-Based

Access

Controls
Step
5
Click
Deploy
Now

to

update

the

rule
for
this

role

or

click
Next
to

deploy

this
rule
and

move
to
another
rule.
Step
6
Click
Deploy
Now

to

update

this

role

and

save

this
configuration
to

the

running-configuration

and
startup-configuration
files.
Related
Topics


Configuring
Device

RBAC

Roles,

page
5-56


Configuring
ACE

Module

and

Appliance

Role-Based

Access

Controls,

page
5-53
Ta
b

l

e


5-21
Rule
Attributes
Attribute
Description
Rule
Number
Number
assigned

to

this

rule.
Permission
Permit
or

deny

the

specified

operation.
Operation
Create,
debug,

modify

1
,

and

monitor

the

specified

feature.
1.
Certain
features

are

not

available

for

certain

operations.

For

modify,

the

following

features

cannot

be

used:

Changeto,

config-copy,

DHCP,
Exec-commands,
NAT,

real-inservice,

routing,

and

syslog.
Feature
AAA,
Access

List,

Change

To

Context,

Config

Copy,

Connection,

DHCP,

Exec-Commands,

Fault
Tolerant,
Inspect,

Interface,

Load

Balance,

NAT,

PKI,

Probe,

Real

Inservice,

Routing,

Real

Server,

Server
Farm,
SSL

2
,

Sticky,

Syslog,

and

VI

P.
The
Changeto

feature

allows

you

to

move

from

the

Admin

context

to

another

virtual

context

and

maintain
the
same

role

with

the

same

privileges

in

the

new

context

that

you

had

in

the

Admin

context.

This

feature
applies
only

to

the

Admin

context

and

to

the

following

ACE

software

versions:


ACE
module
software
Version

A2(1.3)

and

l

ater

releases.


ACE
appliance
software
Version

A3(2.2)

and

l

ater

releases.
The
Exec-commands

feature

enables

all

default

custom

role

commands

in

the

ACE.

The

default

custom
role
commands

are

capture,

debug,

gunzip,

mkdir,

move,

rmkdir,

tac-pac,

untar,

write,

and

undebug.

This
feature
applies

to

both

Admin

and

user

contexts

and

to

the

following

ACE

software

versions:


ACE
module
software
Version

A2(1.3)

and

l

ater

releases.


ACE
appliance
software
Version

A3(2.2)

and

l

ater

releases.
2.
For
all

SSL-related

operations,

a

user

with

a

custom

role

should

include

the

following

two

rules:

A

rule

that

includes

the

SSL

feature,

and

a

rule

that
includes
the

PKI

feature.