Cisco Crosswork Planning 7.2 Collection Setup and Administration

PDF

Cisco Crosswork Planning 7.2 Collection Setup and Administration

Manage users

Want to summarize with AI?

Log in

Provides instructions for managing users, roles, and permissions in Cisco Crosswork Planning, including adding, editing, and deleting user accounts, creating and customizing user roles, and monitoring or terminating active sessions for effective administration.


As a best practice, administrators should create separate accounts for all users. During the creation of a user account, you assign a user role to determine which functionality the user can access. If you are using user roles other than "admin", create the user roles before you add your users (see Create a user role).

Before you begin

Prepare a list of people who will use Cisco Crosswork Planning. Decide on their usernames and preliminary passwords.

Procedure

1.

From the main menu, choose Administration > Users and Roles > Users tab. From this page, you can add a new user, edit the settings for an existing user, or delete a user.

2.

To add a new user:

  1. Click Add icon and enter the required user details.

  2. Click Save.

3.

To edit a user:

  1. Select the check box next to the user name and click Edit icon.

  2. After making changes, click Save.

4.

To delete a user:

  1. Select the check box next to the user name and click Delete icon.

  2. In the confirmation dialog box, click Delete.

5.

To view the audit log for a user:

  1. Click under the Actions column, and select Audit log.

    The Audit Log page appears for the selected user name. For more information, see View the audit log.

User accounts are created, updated, or deleted as required.

Administrative users created during installation

During installation, Cisco Crosswork Planning creates two special administrative user IDs:

  • The virtual machine administrator , with the username cw-admin, and the default password admin. Data center administrators use this ID to log in to and troubleshoot the VM hosting the Crosswork server.

  • The Cisco Crosswork administrator , with the username admin and the default password admin. Product administrators use this ID to log in to the UI, configure the UI, and perform special operations, such as creating new user IDs.

You must change the default password for both administrative user IDs the first time you use them.


User roles, functional categories, and permissions

In Cisco Crosswork Planning, each user account is assigned a user role. This user role controls what the user can do when using the platform and its applications. A user role defines access by combining named functional categories and permissions assigned to each category.

User roles

The Roles page lets users with the appropriate privileges define custom user roles.

As with the default admin role, a custom user role consists of

  • a unique name, such as “Operator” or “admin”

  • one or more selected, named functional categories, which control whether a user with that role has access to the APIs needed to perform specific Cisco Crosswork functions controlled by that API, and

  • one or more selected permissions, which control the scope of what a user with that role can do in the functional category.

For a user role to have access to a functional category, you must select both the category and its underlying API on the Roles page for that role. If a functional category is not selected for a user role, users assigned to that role will not have access to that functional area.

Functional categories

Some functional categories group multiple APIs under one category name. For example, the “AAA” category controls access to the Password Change, Remote Authentication Servers Integration, and Users and Role Management APIs. With this type of category, you can deny access to some of the APIs by leaving them unselected and provide access to others by selecting them. For example, to create an “Operator” role with permission to change their own password, but not to view or change the settings for your installation’s integration with remote AAA servers, or to create new users and roles, select the “AAA” category name. Then, uncheck the “Remote Authentication Server Integration API” and “Users and Role Management API” check boxes.

Permissions

For each role with a selected category, you can define permissions to each underlying functional API on the Roles page.

There are three permission types available per API.

  • Read: lets the user view and interact with the objects controlled by that API, but not change or delete them.

  • Write: lets the user view and change the objects controlled by that API, but not delete them.

  • Delete: lets the user role delete privileges over the objects controlled by that API. Note that the delete permission does not override basic limitations set by the Cisco Crosswork platform and its applications.

Rules for permissions

Although you can mix permissions as you wish, note these rules for permissions.

  • If you select an API for user access, you must provide at least “Read” permission to that API.

  • When you select an API for user access, Cisco Crosswork assumes you want the user to have all permissions on that API and selects all three permissions automatically.

  • If you uncheck all the permissions, including “Read”, Cisco Crosswork assumes that you want to deny access to the API, and unselect it for you.

Recommendations

Cisco recommends these best practices when creating custom user roles.

  • Restrict "Delete" permissions to admin users who have explicit administrative responsibility for maintaining and managing the Cisco Crosswork deployment as a whole.

  • Roles for developers working with all Cisco Crosswork APIs need the same permissions as admin users.

  • Assign at least "Read" and "Write" permissions to roles for users who are actively engaged in managing the network using Cisco Crosswork.

  • Assign read-only access to roles for users who only need to see the data to support their work as system architects or planners.

This table describes some sample custom user roles you should consider creating.

Table 1. Sample custom user roles

Role

Description

Categories/API

Privileges

Operator

Active network manager

All

Read, Write

Monitor

Monitors alerts only

Cisco Crosswork Planning Design and Collector

Read only

API Integrator

All

All

All

Note

Admin role must include permissions for Read, Write, and Delete. Read-write roles need to include both Read and Write permissions.


Create a user role

This topic describes how to create new user roles.

The local "admin" role enables access to all functionality. The system creates this role during installation and you cannot change or delete it. However, you can assign its privileges to new local users. Local users with administrator privileges can create new users as needed (see Manage users). New users created this way can perform only the tasks associated with their assigned user role.

Only local users can create or update user roles. External users authenticated by TACACS, RADIUS, or LDAP cannot modify user roles.

Procedure

1.

From the main menu, choose Administration > Users and Roles > Roles.

The Roles page has a Roles pane on the left side and a corresponding Global API permissions tab on the right side. This tab shows the grouping of user permissions for the selected role.

2.

In the Roles pane, click Add icon to display a new role entry.

3.

Enter a unique name for the new role.

4.

To define the user role's privilege settings, click the Global API permissions tab and follow these steps:

  1. Select the check box for every API that users with this role can access.

    The APIs are grouped logically based on their corresponding application.

  2. For each API, define whether the role has Read, Write, or Delete permission by checking the appropriate check boxes. You can also select an entire API group, such as AAA. All the APIs under the group will be selected with Read,Write, and Delete permissions preselected.

5.

Click Save to create the new role.

The new user role is now available in the Roles list and can be assigned to user IDs.

What to do next

To assign the new user role to one or more user IDs, edit the Role setting for the user IDs (see Edit a user role).


Clone a user role

Cloning an existing user role is the same as creating a new user role, except that you need not set privileges for it. If you like, you can let the cloned user role inherit all the privileges of the original user role.

Cloning user roles is a handy way to create and assign many new user roles quickly. You can

  • clone an existing role multiple times

  • let the cloned user role inherit all the privileges of the original user role

  • assign a name that indicates the role you want a group of users to perform, and

  • edit user IDs of the group of users to assign their new role (see Manage users). Later, edit the roles themselves to give users specific privileges (see Edit a user role).

Note

Some API permissions are predefined in the system admin role and remain unchanged in the cloned role. For example, the system admin role includes the default Read and Write permissions for the Alarms & Events API. These permissions are not configurable for either the original or cloned admin roles.

Procedure

1.

From the main menu, choose Administration > Users and Roles > Roles.

2.

Click an existing role.

3.

Click to create a new duplicate entry in the Roles pane with all the permissions of the original role.

4.

Enter a unique name for the cloned role.

5.

(Optional) Define the role's settings:

  1. Select the check box for every API that the cloned role can access.

  2. For each API, define whether the clone role has Read, Write, and Delete permission by checking the appropriate check boxes. You can also select an entire API group, such as AAA. All APIs under the group will be selected with Read, Write, and Delete permissions preselected.

6.

Click Save to create the newly cloned role.

The newly cloned role is now available in the Roles pane.

Edit a user role

This topic describes how to change the permissions associated with a user role.

Users with administrator privileges can quickly change the privileges of any user role other than the default "admin" role.

Before you begin

Confirm you have administrator privileges.

Procedure

1.

From the main menu, choose Administration > Users and Roles > Roles.

2.

Select an existing role from the left side. The Global API Permissions page on the right side displays the permission settings for the selected role.

3.

Define the role's settings:

  1. Select the check box for every API that users with this role can access.

  2. For each API, define whether the role has Read, Write, or Delete permission by checking the appropriate check boxes. You can also select an entire API group, such as AAA. All the APIs under the group will be selected with Read, Write, and Delete permissions preselected.

4.

Click Save to save the changes.

The selected user role is updated with the new permissions.


Delete a user role

This topic describes how to delete a user role that is no longer needed.

Users with administrator privileges can delete any user role that is not the default "admin" user role or that is not currently assigned to a user ID. To delete a role that is currently assigned to any users, you must first reassign those users to a different user role.

Before you begin

Confirm you have administrator privileges.

Procedure

1.

From the main menu, choose Administration > Users and Roles > Roles.

2.

Select the user role you want to delete.

3.

Click Delete icon.

4.

Click Delete in the confirmation dialog box.

The selected user role is deleted and is no longer available for assignment.

Global API permissions

This table describes the various global API permissions in Cisco Crosswork Planning.

Table 2. Global API permission categories

Category

Global API permissions

Description

AAA

Password Change

Provides permission to manage passwords. The Read and Write permissions are automatically enabled by default. The Delete permission is not applicable to the password change operation. You cannot delete a password, you can only change it.

Remote Authentication Servers Integration

Provides permission to manage remote authentication server configurations in Cisco Crosswork Planning. You must have Read permission to view/read configuration, and Write permission to add/update the configuration of any external authentication server (for example, LDAP, TACACS+) into Cisco Crosswork Planning. The Delete permissions are not applicable for these APIs.

Users and Roles Management

Provides permission to manage users, roles, sessions, and password policies. Supported operations include

  • creating a new user or role

  • updating a user or role

  • deleting a user or role

  • updating task details for a user or role

  • managing sessions (idle-timeout, max session)

  • updating password policy

  • retrieving password tooltip help text

  • retrieving active sessions, and so on

The Read permission allows you to view the content, the Write permission allows you to create and update, and the Delete permission allows you to delete a user or role.

Know my role - Read only

Enables the logged in users to view their permissions or get new permissions.

Write and Delete permissions are not applicable for these APIs.

User Preferences

Allows you to manage the dashlets in the homepage.

The Read permission allows you to view dashboards, the Write permission allows you to edit dashboards, and the Delete permission allows you to delete dashboards.

Administrative Operations

Diagnostic Information

Alarms and Events

Alarms and Events

Allows you to manage system alarms.

Note

The alarms and events associated with the Cisco Crosswork Planning applications are not supported.

Crosswork Planning

Platform

Platform APIs

The Read permission allows you to fetch the server status, node information, application health status, collection job status, certificate information, backup and restore job status, and so on.

The Write permission allows you to

  • enable or disable the xFTP server

  • manage node information (set the login banner, restart a microservice, and so on)

  • manage certificates (export trust store and intermediate key store, create or update certificate, configure the web server, and so on)

  • perform normal/data-only backup and restore operations, and

  • manage applications (activate, deactivate, uninstall, add package, and so on).

The Delete permission allows you to delete a VM (identified by an ID) and remove applications from the software repository.

Views

Manages views in Cisco Crosswork Planning Design.

The Read permission allows you to see views, the Write permission allows you to create or update views, and the Delete permission will enable delete capabilities.


Manage active sessions

This topic describes how to monitor and end sessions of the currently logged-in users.

As an administrator, you can

  • monitor and manage active sessions in the Cisco Crosswork Planning UI

  • terminate a user session, and

  • view the user audit log.

  • Non-admin users with permission to terminate can terminate their own sessions.

  • Non-admin users with read-only permission can only collect the audit log for their sessions.

  • Non-admin users without read permissions cannot view the Active sessions page.

Before you begin

Confirm you have administrator privileges.

Procedure

1.

From the main menu, choose the Administration > Users and Roles > Active sessions tab.

The Active sessions tab displays all currently active sessions with details such as user name, login time, and login method.

Note

The Source IP column appears only when you check the Enable source IP for auditing check box and log in again to Cisco Crosswork Planning. This option is available in the Source IP section of the Administration > AAA > Settings page.

2.

To terminate a user session:

  1. In the Actions column, click and select Terminate.

  2. Click Terminate in the confirmation dialog box.

    • We recommend to use caution while terminating a session. A user whose session is terminated will not receive any prior warning and will lose any unsaved work.

    • Any user whose session is terminated will see this message:

      "Your session has ended. Log into the system again to continue."

3.

To view the audit log for a user, in the Actions column, click and select Audit log.

The Audit Log page appears for the selected user. For more information on Audit Logs, see View the audit log.