ALERT: Some images may not load properly within the Knowledge Base Article. If you see a broken image, please right-click and select 'Open image in a new tab'. We apologize for this inconvenience.

CAS - Admin Account Roles

book

Article ID: 222190

calendar_today

Updated On:

Products

CAS-S400 CAS-S200 CAS-S500 CAS-VA

Issue/Introduction

You can create multiple local user accounts and assign appropriate privileges to restrict access to configuration of the appliance and analysis of data.

A user role specifies the privileges that are granted to a user. With local authentication, you can create user roles for the web UI or for the API only via the CLI.

The table in the resource doc., with URL added at the end of this article, indicates the privileges available in each role.

Environment

Release : 2..x.x.x > 3.1.2.3

Resolution

The "ReadOnly" user account, in Symantec CAS, will be able to view only outputs for services, in the running config. See the snippets below.

https://api-broadcom-ca.wolkenservicedesk.com/attachment/get_attachment_content?uniqueFileId=0BfH6vIqVVlqmTvDyqBWQQ==

https://api-broadcom-ca.wolkenservicedesk.com/attachment/get_attachment_content?uniqueFileId=i6NSMddm/QxdFS+un1Pfzg==

Other "show" output sub-commands available to the "ReadOnly" CAS user account include the below. See the highlighted portion in the snippetbelow.

https://api-broadcom-ca.wolkenservicedesk.com/attachment/get_attachment_content?uniqueFileId=Tx2FnB9KGNk+i/I6vDpNsg==

Note: With the "ReadOnly" role, the user does not have access to the predominantly privilege- & configuration-mode commands. This user will have access only to the "Enable mode, with very limited commands, as already shown in the snippet above. The READ-ONLY user account, by design, does not have access to the cas# show running-config interface CLI command.

For the full details on the user roles in Symantec CAS, please refer to the resource doc. with URL below.

https://techdocs.broadcom.com/us/en/symantec-security-software/web-and-network-security/content-analysis/3-0/admin_tasks_solution/solution_manage_admins/settings_users_local.html