Cisco APIC Security Configuration Guide, Release 6.2(x)

PDF

Cisco APIC Security Configuration Guide, Release 6.2(x)

Access rights workflow dependencies

Want to summarize with AI?

Log in

Describes the coordination requirements between tenant and fabric administrators when RBAC rules restrict access to fabric domains needed for certain configurations.


Access rights workflow dependencies are coordination requirements that occur when Cisco Application Centric Infrastructure (ACI) RBAC rules restrict administrator access to specific fabric domains needed for configuration tasks.

RBAC access scenarios

The ACI RBAC rules enable or restrict access to some or all of the fabric. For example, in order to configure a leaf switch for bare metal server access, the logged in administrator must have rights to the infra domain. By default, a tenant administrator does not have rights to the infra domain. In this case, a tenant administrator who plans to use a bare metal server connected to a leaf switch could not complete all the necessary steps to do so. The tenant administrator would have to coordinate with a fabric administrator who has rights to the infra domain. The fabric administrator would set up the switch configuration policies that the tenant administrator would use to deploy an application policy that uses the bare metal server attached to an ACI leaf switch.


AAA RBAC Roles and Privileges

The Application Policy Infrastructure Controller (APIC) provides the following AAA roles and privileges:

Note

For each of the defined roles in Cisco APIC, the APIC Roles and Privileges Matrix shows which managed object classes can be written and which can be read. The matrix can be found at this URL: https://www.cisco.com/c/dam/en/us/td/docs/Website/datacenter/apicroles/roles.html

Role

Privilege

Description

aaa

aaa

Used for configuring authentication, authorization, accounting, and import/export policies.

admin

admin

Provides full access to all of the features of the fabric. The admin privilege can be considered to be a union of all other privileges.

Role: access-admin

Privilege

Description

access-connectivity-l1

Used for Layer 1 configuration under infra. Example: selectors and port Layer 1 policy configurations.

access-connectivity-l2

Used for Layer 2 configuration under infra. Example: encap configurations on selectors, and attachable entity.

access-connectivity-l3

Used for Layer 3 configuration under infra and static route configurations under a tenant's L3Out.

access-connectivity-mgmt

Used for management infra policies.

access-connectivity-util

Used for tenant ERSPAN policies.

access-equipment

Used for access port configuration.

access-protocol-l1

Used for Layer 1 protocol configurations under infra.

access-protocol-l2

Used for Layer 2 protocol configurations under infra.

access-protocol-l3

Used for Layer 3 protocol configurations under infra.

access-protocol-mgmt

Used for fabric-wide policies for NTP, SNMP, DNS, and image management.

access-protocol-ops

Used for operations-related access policies such as cluster policy and firmware policies.

access-qos

Used for changing CoPP and QoS-related policies.

Role:fabric-admin

Privilege

Description

fabric-connectivity-l1

Used for Layer 1 configuration under the fabric. Example: selectors and port Layer 1 policy and vPC protection.

fabric-connectivity-l2

Used in firmware and deployment policies for raising warnings for estimating policy deployment impact.

fabric-connectivity-l3

Used for Layer 3 configuration under the fabric. Example: Fabric IPv4, IPv6, and MAC protection groups.

fabric-connectivity-mgmt

Used for atomic counter and diagnostic policies on leaf switches and spine switches.

fabric-connectivity-util

Used for atomic counter, diagnostic, and image management policies on leaf switches and spine switches.

fabric-equipment

Used for atomic counter, diagnostic, and image management policies on leaf switches and spine switches.

fabric-protocol-l1

Used for Layer 1 protocol configurations under the fabric.

fabric-protocol-l2

Used for Layer 2 protocol configurations under the fabric.

fabric-protocol-l3

Used for Layer 3 protocol configurations under the fabric.

fabric-protocol-mgmt

Used for fabric-wide policies for NTP, SNMP, DNS, and image management.

fabric-protocol-ops

Used for ERSPAN and health score policies.

fabric-protocol-util

Used for firmware management traceroute and endpoint tracking policies.

tenant-connectivity-util

Used for atomic counter, diagnostic, and image management policies on leaf switches and spine switches.

tenant-connectivity-l2

Used for Layer 2 connectivity changes, including bridge domains and subnets.

tenant-connectivity-l3

Used for Layer 3 connectivity changes, including VRFs.

tenant-protocol-ops

Used for tenant traceroute policies.

Role

Privilege

Description

nw-svc-admin

nw-svc-device

Used for managing Layer 4 to Layer 7 service devices.

nw-svc-devshare

Used for managing shared Layer 4 to Layer 7 service devices.

nw-svc-policy

Used for managing Layer 4 to Layer 7 network service orchestration.

nw-svc-params

nw-svc-params

Used for managing Layer 4 to Layer 7 service policies.

Role: ops

Privilege

Description

ops

Used for viewing the policies configured including troubleshooting policies.

Note

The ops role cannot be used for creating new monitoring and troubleshooting policies. Those policies need to be created by using the admin privilege, just like any other configurations in the Cisco APIC.

Role: read-all

Privilege

Description

access-connectivity-l1

Used for Layer 1 configuration under infra. Example: selectors and port Layer 1 policy configurations.

access-connectivity-l2

Used for Layer 2 configuration under infra. Example: Encap configurations on selectors, and attachable entity.

access-connectivity-l3

Used for Layer 3 configuration under infra and static route configurations under a tenant's L3Out.

access-connectivity-mgmt

Used for management infra policies.

access-connectivity-util

Used for tenant ERSPAN policies.

access-equipment

Used for access port configuration.

access-protocol-l1

Used for Layer 1 protocol configurations under infra.

access-protocol-l2

Used for Layer 2 protocol configurations under infra.

access-protocol-l3

Used for Layer 3 protocol configurations under infra.

access-protocol-mgmt

Used for fabric-wide policies for NTP, SNMP, DNS, and image management.

access-protocol-ops

Used for operations-related access policies such as cluster policy and firmware policies.

access-qos

Used for changing CoPP and QoS-related policies.

fabric-connectivity-l1

Used for Layer 1 configuration under the fabric. Example: selectors and port Layer 1 policy and vPC protection.

fabric-connectivity-l2

Used in firmware and deployment policies for raising warnings for estimating policy deployment impact.

fabric-connectivity-l3

Used for Layer 3 configuration under the fabric. Example: Fabric IPv4, IPv6, and MAC protection groups.

fabric-protocol-l1

Used for Layer 1 protocol configurations under the fabric.

fabric-protocol-l2

Used for Layer 2 protocol configurations under the fabric.

fabric-protocol-l3

Used for Layer 3 protocol configurations under the fabric.

nw-svc-device

Used for managing Layer 4 to Layer 7 service devices.

nw-svc-devshare

Used for managing shared Layer 4 to Layer 7 service devices.

nw-svc-params

Used for managing Layer 4 to Layer 7 service policies.

nw-svc-policy

Used for managing Layer 4 to Layer 7 network service orchestration.

ops

Used for viewing the policies configured including troubleshooting policies.

Note

The ops role cannot be used for creating new monitoring and troubleshooting policies. Those policies need to be created by using the admin privilege, just like any other configurations in the Cisco APIC.

tenant-connectivity-util

Used for atomic counter, diagnostic, and image management policies on leaf switches and spine switches.

tenant-connectivity-l2

Used for Layer 2 connectivity changes, including bridge domains and subnets.

tenant-connectivity-l3

Used for Layer 3 connectivity changes, including VRFs.

tenant-connectivity-mgmt

Used for tenant in-band and out-of-band management connectivity configurations and for debugging/monitoring policies such as atomic counters and health score.

tenant-epg

Used for managing tenant configurations such as deleting/creating endpoint groups.

tenant-ext-connectivity-l1

Used for write access firmware policies.

tenant-ext-connectivity-l2

Used for managing tenant L2Out configurations.

tenant-ext-connectivity-l3

Used for managing tenant L3Out configurations.

tenant-ext-connectivity-mgmt

Used as write access for firmware policies.

tenant-ext-connectivity-util

Used for debugging/monitoring/observer policies such as traceroute, ping, oam, and eptrk.

tenant-ext-protocol-l1

Used for managing tenant external Layer 1 protocols. Generally only used for write access for firmware policies.

tenant-ext-protocol-l2

Used for managing tenant external Layer 2 protocols. Generally only used for write access for firmware policies.

tenant-ext-protocol-l3

Used for managing tenant external Layer 3 protocols such as BGP, OSPF, PIM, and IGMP.

tenant-ext-protocol-mgmt

Used as write access for firmware policies.

tenant-ext-protocol-util

Used for debugging/monitoring/observer policies such as traceroute, ping, oam, and eptrk.

tenant-network-profile

Used for managing tenant configurations, such as deleting and creating network profiles, and deleting and creating endpoint groups.

tenant-protocol-l1

Used for managing configurations for Layer 1 protocols under a tenant.

tenant-protocol-l2

Used for managing configurations for Layer 2 protocols under a tenant.

tenant-protocol-l3

Used for managing configurations for Layer 3 protocols under a tenant.

tenant-protocol-mgmt

Only used as write access for firmware policies.

tenant-protocol-ops

Used for tenant traceroute policies.

tenant-QoS

Used for QoS-related configurations for a tenant.

tenant-security

Used for contract-related configurations for a tenant.

vmm-connectivity

Used to read all the objects in Cisco APIC's VMM inventory required for virtual machine connectivity.

vmm-ep

Used to read virtual machine and hypervisor endpoints in the Cisco APIC's VMM inventory.

vmm-policy

Used for managing policies for virtual machine networking.

vmm-protocol-ops

Not used by VMM policies.

vmm-security

Used for managing authentication policies for VMM, such as the username and password for VMware vCenter.

Role: tenant-admin

Privilege

Description

aaa

Used for configuring authentication, authorization, accouting and import/export policies.

access-connectivity-l1

Used for Layer 1 configuration under infra. Example: selectors and port Layer 1 policy configurations.

access-connectivity-l2

Used for Layer 2 configuration under infra. Example: Encap configurations on selectors, and attachable entity.

access-connectivity-l3

Used for Layer 3 configuration under infra and static route configurations under a tenant's L3Out.

access-connectivity-mgmt

Used for management infra policies.

access-connectivity-util

Used for tenant ERSPAN policies.

access-equipment

Used for access port configuration.

access-protocol-l1

Used for Layer 1 protocol configurations under infra.

access-protocol-l2

Used for Layer 2 protocol configurations under infra.

access-protocol-l3

Used for Layer 3 protocol configurations under infra.

access-protocol-mgmt

Used for fabric-wide policies for NTP, SNMP, DNS, and image management.

access-protocol-ops

Used for operations-related access policies such as cluster policy and firmware policies.

access-qos

Used for changing CoPP and QoS-related policies.

fabric-connectivity-l1

Used for Layer 1 configuration under the fabric. Example: selectors and port Layer 1 policy and vPC protection.

fabric-connectivity-l2

Used in firmware and deployment policies for raising warnings for estimating policy deployment impact.

fabric-connectivity-l3

Used for Layer 3 configuration under the fabric. Example: Fabric IPv4, IPv6, and MAC protection groups.

fabric-connectivity-mgmt

Used for atomic counter and diagnostic policies on leaf switches and spine switches.

fabric-connectivity-util

Used for atomic counter, diagnostic, and image management policies on leaf switches and spine switches.

fabric-equipment

Used for atomic counter, diagnostic, and image management policies on leaf switches and spine switches.

fabric-protocol-l1

Used for Layer 1 protocol configurations under the fabric.

fabric-protocol-l2

Used for Layer 2 protocol configurations under the fabric.

fabric-protocol-l3

Used for Layer 3 protocol configurations under the fabric.

fabric-protocol-mgmt

Used for fabric-wide policies for NTP, SNMP, DNS, and image management.

fabric-protocol-ops

Used for ERSPAN and health score policies.

fabric-protocol-util

Used for firmware management traceroute and endpoint tracking policies.

nw-svc-device

Used for managing Layer 4 to Layer 7 service devices.

nw-svc-devshare

Used for managing shared Layer 4 to Layer 7 service devices.

nw-svc-params

Used for managing Layer 4 to Layer 7 service policies.

nw-svc-policy

Used for managing Layer 4 to Layer 7 network service orchestration.

ops

Used for viewing the policies configured including troubleshooting policies.

Note

The ops role cannot be used for creating new monitoring and troubleshooting policies. Those policies need to be created by using the admin privilege, just like any other configurations in the Cisco APIC.

tenant-connectivity-util

Used for atomic counter, diagnostic, and image management policies on leaf switches and spine switches.

tenant-connectivity-l2

Used for Layer 2 connectivity changes, including bridge domains and subnets.

tenant-connectivity-l3

Used for Layer 3 connectivity changes, including VRFs.

tenant-connectivity-mgmt

Used for tenant in-band and out-of-band management connectivity configurations and for debugging/monitoring policies such as atomic counters and health score.

tenant-epg

Used for managing tenant configurations such as deleting/creating endpoint groups.

tenant-ext-connectivity-l1

Used for write access firmware policies.

tenant-ext-connectivity-l2

Used for managing tenant L2Out configurations.

tenant-ext-connectivity-l3

Used for managing tenant L3Out configurations.

tenant-ext-connectivity-mgmt

Used as write access for firmware policies.

tenant-ext-connectivity-util

Used for debugging/monitoring/observer policies such as traceroute, ping, oam, and eptrk.

tenant-ext-protocol-l1

Used for managing tenant external Layer 1 protocols. Generally only used for write access for firmware policies.

tenant-ext-protocol-l2

Used for managing tenant external Layer 2 protocols. Generally only used for write access for firmware policies.

tenant-ext-protocol-l3

Used for managing tenant external Layer 3 protocols such as BGP, OSPF, PIM, and IGMP.

tenant-ext-protocol-mgmt

Used as Write access for firmware policies.

tenant-ext-protocol-util

Used for debugging/monitoring/observer policies such as traceroute, ping, oam, and eptrk.

tenant-network-profile

Used for managing tenant configurations, such as deleting and creating network profiles, and deleting and creating endpoint groups.

tenant-protocol-l1

Used for managing configurations for Layer 1 protocols under a tenant.

tenant-protocol-l2

Used for managing configurations for Layer 2 protocols under a tenant.

tenant-protocol-l3

Used for managing configurations for Layer 3 protocols under a tenant.

tenant-protocol-mgmt

Only used as write access for firmware policies.

tenant-protocol-ops

Used for tenant traceroute policies.

tenant-QoS

Used for QoS-related configurations for a tenant.

tenant-security

Used for contract-related configurations for a tenant.

vmm-connectivity

Used to read all the objects in Cisco APIC's VMM inventory required for virtual machine connectivity.

vmm-ep

Used to read virtual machine and hypervisor endpoints in the Cisco APIC's VMM inventory.

vmm-policy

Used for managing policies for virtual machine networking.

vmm-protocol-ops

Not used by VMM policies.

vmm-security

Used for managing authentication policies for VMM, such as the username and password for VMware vCenter.

Role: tenant-ext-admin

Privilege

Description

tenant-connectivity-util

Used for atomic counter, diagnostic, and image management policies on leaf switches and spine switches.

tenant-connectivity-l2

Used for Layer 2 connectivity changes, including bridge domains and subnets.

tenant-connectivity-l3

Used for Layer 3 connectivity changes, including VRFs.

tenant-connectivity-mgmt

Used for tenant in-band and out-of-band management connectivity configurations and for debugging/monitoring policies such as atomic counters and health score.

tenant-epg

Used for managing tenant configurations such as deleting/creating endpoint groups.

tenant-ext-connectivity-l1

Used for write access firmware policies.

tenant-ext-connectivity-l2

Used for managing tenant L2Out configurations.

tenant-ext-connectivity-l3

Used for managing tenant L3Out configurations.

tenant-ext-connectivity-mgmt

Used as write access for firmware policies.

tenant-ext-connectivity-util

Used for debugging/monitoring/observer policies such as traceroute, ping, oam, and eptrk.

tenant-ext-protocol-l1

Used for managing tenant external Layer 1 protocols. Generally only used for write access for firmware policies.

tenant-ext-protocol-l2

Used for managing tenant external Layer 2 protocols. Generally only used for write access for firmware policies.

tenant-ext-protocol-l3

Used for managing tenant external Layer 3 protocols such as BGP, OSPF, PIM, and IGMP.

tenant-ext-protocol-mgmt

Used as Write access for firmware policies.

tenant-ext-protocol-util

Used for debugging/monitoring/observer policies such as traceroute, ping, oam, and eptrk.

tenant-network-profile

Used for managing tenant configurations, such as deleting and creating network profiles, and deleting and creating endpoint groups.

tenant-protocol-l1

Used for managing configurations for Layer 1 protocols under a tenant.

tenant-protocol-l2

Used for managing configurations for Layer 2 protocols under a tenant.

tenant-protocol-l3

Used for managing configurations for Layer 3 protocols under a tenant.

tenant-protocol-mgmt

Only used as write access for firmware policies.

tenant-protocol-ops

Used for tenant traceroute policies.

tenant-QoS

Used for QoS-related configurations for a tenant.

tenant-security

Used for contract-related configurations for a tenant.

vmm-connectivity

Used to read all the objects in Cisco APIC's VMM inventory required for virtual machine connectivity.

vmm-ep

Used to read virtual machine and hypervisor endpoints in the Cisco APIC's VMM inventory.

vmm-policy

Used for managing policies for virtual machine networking.

vmm-protocol-ops

Not used by VMM policies.

vmm-security

Used for managing authentication policies for VMM, such as the username and password for VMware vCenter.

Role: vmm-admin

Privilege

Description

vmm-connectivity

Used to read all the objects in Cisco APIC's VMM inventory required for virtual machine connectivity.

vmm-ep

Used to read virtual machine and hypervisor endpoints in the Cisco APIC's VMM inventory.

vmm-policy

Used for managing policies for virtual machine networking.

vmm-protocol-ops

Not used by VMM policies.

vmm-security

Used for managing authentication policies for a VMM, such as the username and password for VMware vCenter.


Custom roles

A custom role is a security mechanism that

  • enables creation of user-defined roles with assigned privileges

  • assigns privileges to managed object classes through interface access attributes, and

  • applies privilege bits at compile time per class rather than per instance or object.

Privilege bit support matrix

In addition to the 45 privilege bits, the "AAA" privilege bit applies to all AAA-subsystem configuration and read operations. This table provides a matrix of the supported privilege combinations. The rows in the table represent Cisco Application Centric Infrastructure (ACI) modules and the columns represent functionality for a given module. A value of "Yes" in a cell indicates that the functionality for the module is accessible and there exists a privilege bit to access that functionality. An empty cell indicates that the particular functionality for module is not accessible by any privilege bit.

Connectivity

QoS

Security

Application

Fault

Stats

Provider

Service Profile

Service Chain

VMM

Yes

Yes

Yes

Yes

Yes

Fabric

Yes

Yes

Yes

Yes

Yes

Yes

Yes

External

Yes

Yes

Yes

Yes

Yes

Yes

Tenant

Yes

Yes

Yes

EPG, NP

Yes

Yes

Yes

Infra

Yes

Yes

Yes

Yes

Yes

Yes

Yes

Ops

Yes

Yes

Storage

Yes

Yes

Yes

Yes

Yes

Yes

Network Service

Yes

Yes

Yes

Yes

Yes

Yes

Yes


Selectively expose physical resources across security domains

Selectively exposing physical resources across security domains is a capability that

  • uses RBAC rules to provide access to physical resources for users in different security domains

  • enables fabric-wide administrators to grant cross-domain access to otherwise inaccessible resources, and

  • consists of two parts: the distinguished name (DN) that locates the object plus the name of the security domain containing the accessing user.

Cross-domain access mechanism

A fabric-wide administrator uses RBAC rules to selectively expose physical resources to users that otherwise are inaccessible because they are in a different security domain.

When designated users in a security domain are logged in, the RBAC rule gives them access to the specified domain as well as all its child objects in the tree. To give users in multiple security domains access to the same domain, the fabric-wide administrator creates an RBAC rule for each security domain that contains the DN for the target domain plus the security domain.

Note

While an RBAC rule exposes an object to a user in a different part of the management information tree, it is not possible to use the CLI to navigate to such an object by traversing the structure of the tree. However, as long as the user knows the DN of the object included in the RBAC rule, the user can use the CLI to locate it via an MO find command.

VMM domain access example

If a user in tenant Solar needs access to a virtual machine management (VMM) domain, the fabric-wide admin could create an RBAC rule to allow this. The RBAC rule would include the DN for the VMM domain plus the Solar security domain name.


Enable sharing of services across security domains