Field
Description
Usage tips
Access
level
The access level given to members of the
administrator group:
Read-write
: allows all configuration information to be
viewed and changed. This provides the same rights as
the default
admin
account.
Read-only
: allows status and configuration information
to be viewed only and not changed. Some pages, such
as the
Upgrade
page, are blocked to read-only
accounts.
Auditor
: allows access to the
Event Log
,
Configuration
Log
,
Network Log
,
Alarms
and
Overview
pages only .
None
: no access is allowed.
Default:
Read-write
If an administrator belongs to more than one
group, it is assigned the highest level
permission for each of the access settings
across all of the groups to which it belongs
(any groups in a disabled state are ignored).
See
Determining the access level for
accounts that belong in multiple groups
[p.269]
below for more information.
Web
access
Determines whether members of this group are
allowed to log in to the system using the web interface.
Default:
Yes
API
access
Determines whether members of this group are
allowed to access the system's status and
configuration using the Application Programming
Interface (API).
Default:
Yes
This controls access to the XML and REST
APIs by systems such as Cisco TMS.
State
Indicates if the group is enabled or disabled. Access
will be denied to members of disabled groups.
If an administrator account belongs to more
than one administrator group with a
combination of both
Enabled
and
Disabled
states, their access will be
Enabled
.
Determining the access level for accounts that belong in multiple groups
If an administrator account belongs to more than one administrator group, the effective settings for
Access
level
,
Web access
and
API access
will be the highest of each group to which the account belongs. Any
groups in a disabled state are ignored.
For example, if the following groups were configured:
Group name
Access level
Web access
API access
Administrators
Read-write
-
-
Region A
Read-only
Yes
-
Region B
Read-only
-
Yes
Region C
Read-only
Yes
Yes
the following table shows examples of the access permissions that would be granted for accounts that
belong in one or more of those groups:
Groups belonged to
Access permissions granted
Administrators
and
Region A
read-write access to the web interface but no API access
Cisco VCS Administrator Guide (X8.1.1)
Page 269 of 507
User accounts
Configuring remote account authentication using LDAP