Using Management Center for VPN Routers 1.3
Router MC User Permissions

Table Of Contents

Router MC User Permissions

CiscoWorks Server Roles and Router MC Permissions

ACS Roles and Router MC Permissions


Router MC User Permissions


To log into Router MC, your username and password must be authenticated. After authentication, Router MC establishes what your role is within the application. This role defines the set of Router MC tasks or operations that you are authorized to do. If you are not authorized for certain Router MC tasks or for certain devices, the related Router MC menu items, TOC items, and buttons will be hidden or disabled.

Authentication and authorization for Router MC is managed either by the CiscoWorks server or by the Cisco Secure Access Control Server (ACS). By default, authentication and authorization is managed by CiscoWorks. You can change to ACS using CiscoWorks Common Services. See the documentation for CiscoWorks Common Services for details on how to specify ACS for authentication and authorization.

User permissions for Router MC are described in the following topics:

CiscoWorks Server Roles and Router MC Permissions

ACS Roles and Router MC Permissions

CiscoWorks Server Roles and Router MC Permissions

CiscoWorks has five role types corresponding to likely functions within your organization:

Help desk—User has read-only access for viewing devices, device groups, and the entire scope of a VPN.

Approver—User can review policy changes, and either approve or reject them. User can also approve or reject deployment jobs.

Network operator—User can make policy changes (but not device inventory changes) and create and deploy jobs. Note that a network operator's activities and jobs must be approved by an Approver.

System administrator—User can perform CiscoWorks server tasks and can make changes to the device hierarchy (such as move or delete devices). The system administrator can also change administrative settings.

Network administrator—User can perform all CiscoWorks server and Router MC tasks. A network administrator can also add users to the system with CiscoWorks or ACS, set user passwords and assign user roles and privileges.

Table A-1 shows how Router MC permissions are mapped to these roles in ACS.

ACS Roles and Router MC Permissions

Cisco Secure Access Control Server (ACS) supports application-specific roles. Each role is made up of a set of permissions that determine the role's level of access to Router MC tasks. Each user group is assigned a role and each user in the group can perform Router MC actions based on the permissions in the role.

Furthermore, these roles can be assigned to ACS device groups, allowing permissions to be differentiated on different sets of devices. ACS device groups are completely independent of Router MC device groups.


Note ACS 3.1 must be installed for Router MC authorization.


Router MC provides default roles and permissions in ACS. Some permissions must be configured on the managed devices and others on the Router MC Management Station, as specified below. The available Router MC permissions in ACS are as follows:

View ConfigUser can view settings and policies but cannot make changes.

View AdminUser can view Router MC application settings. This permission must be configured on the Router MC Management Station.

View CLI—User can view the current and previous configuration on managed devices and can preview the CLI commands to be generated for or deployed to the devices by Router MC.

Modify ConfigUser can define and modify policies.

Modify Device-ListUser make changes to the Router MC device inventory. This permission must be configured on the Router MC Management Station.

Modify AdminUser can modify Router MC application settings. This permission must be configured on the Router MC Management Station.

Approve ActivityUser can approve activities. This permission must be configured on the Router MC Management Station.

Approve JobUser can approve jobs. This permission must be configured on the Router MC Management Station.

DeployUser can deploy VPN and firewall policy configurations to devices or files.

These permissions are mapped to roles in ACS. These roles are the same as the CiscoWorks roles (see CiscoWorks Server Roles and Router MC Permissions).

Table A-1 describes Router MC permissions, the Router MC tasks allowed for each permission, and the CiscoWorks roles to which the permissions are mapped.

Table A-1 Router MC Permissions and Associated Roles 

Router MC Permission in ACS
Permitted Router MC Tasks
Help Desk
Approver
Network Operator
System Admin
Network Admin

View Config

Activity and Job Workflow:

View activities.

View jobs.

Create a job to generate configurations.

View job status.

VPN and Firewall Settings and Policies:

View settings and policies in the Configuration tab.

Yes

Yes

Yes

Yes

Yes

View Admin

View administrative settings for the Router MC application, in the Admin tab.

Yes

Yes

Yes

Yes

Yes

View CLI

View CLI commands for policy definitions, per activity, in the Configuration tab.

View the CLI commands generated for the devices in a deployment job, in the Deployment tab.

No

Yes

Yes

Yes

Yes

Modify Config

Device Management:

Specify device credentials.

Import devices (also need Modify Device-List permission).

Reimport devices.

Edit devices.

Move and delete devices (also need Modify Device-List permission).

Create device groups (also need Modify Device-List permission).

Delete device groups (also need Modify Device-List permission).

Activity and Job Workflow:

Create and submit activity.

Delete activity.

No

No

Yes

No

Yes

Modify Config (cont.)

VPN and Firewall Settings and Policies:

Define/modify general, hub, and spoke settings.

Create/modify IKE and VPN tunnel policies.

Create/modify access rules.

Create/modify transform sets.

Create/modify translation rules.

Create/modify network groups.

Upload policies to target device.

No

No

Yes

No

Yes

Modify Device-List

Device Management:

Import devices (also need Modify Config permission).

Move and delete devices (also need Modify Config permission).

Create device groups (also need Modify Config permission).

Delete device groups (also need Modify Config permission).

Add unmanaged spoke.

Activity Workflow:

Create activity.

Submit activity.

Delete activity.

No

No

No

Yes

Yes

Modify Admin

Administration:

Modify administrative settings for the Router MC application.

Activity Workflow:

Close an activity opened by another user.

No

No

No

Yes

Yes

Approve Activity

Approve a submitted activity, thereby committing its policy configurations to the database.

Reject a submitted activity.

No

Yes

No

No

Yes

Approve Job

Approve a job so that it can be deployed.

No

Yes

No

No

Yes

Deploy

Deploy job to devices or files.

Redeploy job.

Rollback job.

No

No

Yes

No

Yes