Cisco APIC Security Configuration Guide, Release 6.2(x)

PDF

Cisco APIC Security Configuration Guide, Release 6.2(x)

Guidelines and limitations for security domains and node rules

Want to summarize with AI?

Log in

Describes guidelines and limitations for configuring security domains and node rules. Helps users avoid configuration issues and understand user access restrictions.


When configuring security domains and node rules, follow these guidelines and limitations. In this section, a "restricted node user" is a user in a restricted security domain to which a node has been assigned.

  • When upgrading from an earlier Cisco Application Policy Infrastructure Controller ( APIC ) release to a 5.0 release, you must reconfigure any rules, policies, or roles that use the more granular earlier privileges.

  • When downgrading from a Cisco APIC 5.0 release to an earlier release, you must manually edit and retain default roles. Roles modified under a Cisco APIC 5.0 release are retained.

  • A spine switch cannot be assigned using RBAC node rules.

  • When creating RBAC node rules, you should not assign a node to more than one security domain.

  • A restricted node user can configure only policies. An admin user should perform node configuration and troubleshooting.

  • A restricted node user can access default system-created managed objects.

  • A restricted node user can view fabric-level fault counts in the Fault Dashboard.

  • A restricted node user can view node-level faults, such as those from AAA servers, NTP servers, and DNS servers.

  • If an admin or nonrestricted domain user associates a relationship policy to an access policy created by a restricted node user, that policy will be visible to the restricted node user.

  • You cannot configure a restricted node user using the CLI.

  • By default, the port-mgmt role has the custom-port-privilege privilege that contains predefined access policy managed objects. You can add more managed objects using the procedure in Configure a custom privilege .