Explains how to implement role-based access control through security domains and node rules to restrict user access to specific network devices and resources.
Restricting access by domains
Describes how security domains enable fabric administrators to control user access to Cisco ACI resources. Provides context for multi-tenancy and resource separation in complex environments.
Assigning a Node to a Domain
Learn how to assign a fabric node to a security domain.
Guidelines and limitations for security domains and node rules
Describes guidelines and limitations for configuring security domains and node rules. Helps users avoid configuration issues and understand user access restrictions.
Create a security domain
Creates a security domain to control access to Cisco ACI resources. This task enables administrators to define domain boundaries for user access and policy visibility.
Create a node rule to assign access to a node
Configures a node rule that assigns a fabric node to a security domain. This enables role-based access control for physical nodes such as leaf switches within the specified domain.
Creating a Custom Role with Custom Privileges
Configures a custom role and assigns a specific set of privileges to that role. This process enables administrators to define granular access control based on organizational requirements.
Configure a custom privilege
Configures a custom privilege for role-based access control, allowing assignment of read or write permissions to managed object classes not covered by predefined privileges.
Use case example of configuring an RBAC node rule
Describes a practical scenario for configuring RBAC node rules to control user access to specific tenants and leaf nodes. Provides step-by-step guidance and highlights access behaviors for different users.