2.3.1 Roles

Information

A role consists of rules that permit or deny access to a set of commands within specified command modes.

For local users a role limits the commands they can run to the appropriate set for their job.

Additional custom roles can be defined as needed or AAA services - such as TACACS+ - can be used to provide more granular access to the switch.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Assign roles to local users with the username command

username name [PRIVILEGE_LEVEL] SECURITY [ROLE_USER]

SECURITY specifies the password assignment.

Impact:

Incorrect assignment of roles can prevent users performing required functions or allow users to perform actions they should not.

See Also

https://workbench.cisecurity.org/benchmarks/25683

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6

Plugin: Arista

Control ID: f47671b213cecacf0046a1c2a4b5955d89762855d1ac3e443ffb4f409715f57c