Re: [j-nsp] command authorization and tacacs

2018-12-13 Thread Timur Maryin via juniper-nsp
Hi Pierfrancesco, Timur> 2. commit script which checks presence of certain parts of config. I'll need to refresh myself on this and see if I can use this technique. There is an example on github which can be used as starting point: https://github.com/Juniper/junoscriptorium/blob/maste

Re: [j-nsp] command authorization and tacacs

2018-12-12 Thread Pierfrancesco Caci
Hi Timur > "Timur" == Timur Maryin writes: Timur> Hello! Timur> On 11-Dec-18 15:33, Pierfrancesco Caci wrote: >> >> I have not found a way to prevent a user from accidentally delete entire >> bgp config, but still allowing him to operate on single neighbors. Or >>

Re: [j-nsp] command authorization and tacacs

2018-12-12 Thread Timur Maryin via juniper-nsp
Hello! On 11-Dec-18 15:33, Pierfrancesco Caci wrote: I have not found a way to prevent a user from accidentally delete entire bgp config, but still allowing him to operate on single neighbors. Or other similar situation involving top level configuration vs details inside each block. There a

[j-nsp] command authorization and tacacs

2018-12-11 Thread Pierfrancesco Caci
Hello, I'm trying to set up command authorization via tacacs on MX and PTX series. Tacacs is provided by Cisco ACS. I fully understand that Juniper doesn't authorize the commands one by one, and instead it relies on classes, permissions, and strings/regexps of allowed or denied commands, and thi