{"id":284,"date":"2018-07-14T11:12:32","date_gmt":"2018-07-14T11:12:32","guid":{"rendered":"https:\/\/www.bestpath.io\/?p=284"},"modified":"2023-06-07T13:33:11","modified_gmt":"2023-06-07T13:33:11","slug":"cisco-aci-rbac","status":"publish","type":"post","link":"https:\/\/bestpath.io\/cisco-aci-rbac\/","title":{"rendered":"Cisco ACI role based access control (RBAC)"},"content":{"rendered":"<div id=\"pl-284\"  class=\"panel-layout\" ><div id=\"pg-284-0\"  class=\"panel-grid panel-has-style\" ><div data-tab-animation=\"none\" class=\"panel-row-style panel-row-style-for-284-0\" ><div id=\"pgc-284-0-0\"  class=\"panel-grid-cell\" ><div id=\"panel-284-0-0-0\" class=\"widget_text so-panel widget widget_custom_html panel-first-child panel-last-child\" data-index=\"0\" ><div data-tab-animation=\"none\" class=\"widget_text panel-widget-style panel-widget-style-for-284-0-0-0\" ><div class=\"textwidget custom-html-widget\"><style>\n\n\tbody {\n\t\tfont-family: 'Noto Sans', sans-serif !important;\n\t}\n\th1 {\n\t\tfont-family: 'Noto Sans',sans-serif!important;\n    font-size: 63px;\n    line-height: 73px;\n    text-shadow: 2px 2px 5px rgb(0 0 0 \/ 26%);\n\t}\n\t\n\th2 {\n    font-family: 'Noto Sans',sans-serif!important;\n    font-size: 36px;\n    line-height: 35px;\n    border-bottom: 5px solid #ec672c;\n    letter-spacing: -1px;\n    padding: 0 0 10px 0;\n    display: inline-block;\n}\n\t\t\n\th3 {\n\t\tfont-family: 'Noto Sans',sans-serif!important;\n    font-size: 19px;\n    line-height: 27px;\n    letter-spacing: -0.5px;\n}\n\t\n\th4 {\n\t\tfont-family: 'Noto Sans',sans-serif!important;\n    font-size: 19px;\n    line-height: 31px;\n    font-weight: 600;\n}\n\th6 {\n\t\tfont-family: 'Noto Sans',sans-serif!important;\n    font-weight: 400;\n    font-size: 18px;\n    line-height: 23px;\n\t\tmargin: 10px 0 22px 0;\n\n}\n\t\n.page-content p {\n\t\tfont-size: 16px;\n    line-height: 20px;\n\t}\n\t\n\t.ow-button-base a {\n\t\t\/*border: 2px solid #fff !important; *\/\n\t}\n\t\n\t.iconboxes {\n\t\tborder-radius:10px;\n\t\tmin-height: 389px\n\t}\n\t\n\t\t@media (max-width: 1024px) {\n\t\t\t\t\th1 {\n    font-size: 50px;\n    line-height: 56px;\n\t\t}\n\t}\n\t\n\t\n\t@media (max-width: 780px) {\n\t\t\n\t\th1 {\n    font-size: 39px;\n    line-height: 47px;\n\t\t}\n\t\t\n\t\t\n\t\t.iconboxes {\n\t\tmin-height: initial;\n\t}\n\t\t\n\t\th2 {\n\t\tfont-size: 28px;\n    line-height: 32px;\n}\n\t\t\n\t}\n\t\n\t\n\t\t@media (max-width: 500px) {\n\t\t\n\t\th1 {\n    font-size: 32px;\n    line-height: 38px;\n\t\t}\n\t}\n<\/style><\/div><\/div><\/div><\/div><\/div><\/div><div id=\"pg-284-1\"  class=\"panel-grid panel-has-style\" ><div class=\"siteorigin-panels-stretch fixed-height fixed-height-align-top panel-row-style panel-row-style-for-284-1\" style=\"background-repeat:no-repeat;height:350px;\" data-stretch-type=\"full-stretched\" data-tab-animation=\"none\" data-fixed-height-mobile=\"200\" ><div id=\"pgc-284-1-0\"  class=\"panel-grid-cell\" ><div id=\"panel-284-1-0-0\" class=\"so-panel widget widget_text panel-first-child panel-last-child\" data-index=\"1\" ><div data-tab-animation=\"none\" class=\"panel-widget-style panel-widget-style-for-284-1-0-0\" >\t\t\t<div class=\"textwidget\"><\/div>\n\t\t<\/div><\/div><\/div><\/div><\/div><div id=\"pg-284-2\"  class=\"panel-grid panel-has-style\" ><div data-tab-animation=\"none\" class=\"panel-row-style panel-row-style-for-284-2\" ><div id=\"pgc-284-2-0\"  class=\"panel-grid-cell\" ><div id=\"panel-284-2-0-0\" class=\"so-panel widget widget_sow-editor panel-first-child panel-last-child\" data-index=\"2\" ><div data-tab-animation=\"none\" class=\"panel-widget-style panel-widget-style-for-284-2-0-0\" ><div\n\t\t\t\n\t\t\tclass=\"so-widget-sow-editor so-widget-sow-editor-base\"\n\t\t\t\n\t\t>\n<div class=\"siteorigin-widget-tinymce textwidget\">\n\t<h2 style=\"text-align: left;\">ACI Role Based Access Control (RBAC)<\/h2>\n<\/div>\n<\/div><\/div><\/div><\/div><\/div><\/div><div id=\"pg-284-3\"  class=\"panel-grid panel-has-style\" ><div data-tab-animation=\"none\" class=\"panel-row-style panel-row-style-for-284-3\" ><div id=\"pgc-284-3-0\"  class=\"panel-grid-cell\" ><div id=\"panel-284-3-0-0\" class=\"so-panel widget widget_sow-editor panel-first-child panel-last-child\" data-index=\"3\" ><div data-tab-animation=\"none\" class=\"panel-widget-style panel-widget-style-for-284-3-0-0\" ><div\n\t\t\t\n\t\t\tclass=\"so-widget-sow-editor so-widget-sow-editor-base\"\n\t\t\t\n\t\t>\n<div class=\"siteorigin-widget-tinymce textwidget\">\n\t<p>We want to give some insight into the Role Based Access Control (RBAC) functionality.\u00a0Cisco ACI is designed to be multi-tenancy which means being able to host a number of different customers or business units (with different networking requirements and business practices) on a single fabric.<\/p>\n<p>We have seen that even within a single Enterprise, different business units operate with different levels of agility with often contrasting business requirements. For example; some teams may be embracing automation with latest technologies whilst other teams may consider stability as a priority. Granted, these two working practices are not mutually exclusive but more traditional departments may consider them to be.\u00a0In modern networks, with automation as ubiquitous as it is, businesses want to move away from traditional network task provisioning. E.g waiting five days for a firewall rule to be added or another five days for a new VLAN to be provisioned. As different business units (potentially tenants) look to automate provisioning, an emphasis is placed on RBAC to reduce the configuration error blast radius.<\/p>\n<p>From an ACI perspective, multitenancy environments work best when full control for a tenant is handed over to a business unit. This allows them to operate under their own business processes with various levels of agility and their own change control windows. If full control is handed over to the business unit, then it\u2019s imperative that the administrative change domain (and fault domain) is scoped appropriately.<\/p>\n<p>This begs the question; How is the configuration of Tenant A isolated from the configuration of Tenant B?\u00a0ACI facilitates RBAC by leveraging a few core APIC concepts:<\/p>\n<h3>RBAC core components<\/h3>\n<p><strong>Users:\u00a0<\/strong>These can be stored locally on the APIC or read from an external repository.<\/p>\n<p><strong>Privileges:\u00a0<\/strong>Predefined sets of object model classes within the MIT (Management Information Tree) which can be accessed. For example, there is a default Privilege called \u2018tenant-security\u2019. This Privilege controls access to contract related configurations. It is not possible to create your own privileges, only to reuse existing \u2018out of the box\u2019 privileges. Details of all of the predefined privileges are documented in the APIC\u00a0<a href=\"https:\/\/www.cisco.com\/c\/en\/us\/td\/docs\/switches\/datacenter\/aci\/apic\/sw\/2-x\/Security_config\/b_Cisco_APIC_Security_Guide.html\">documentation<\/a>.<\/p>\n<p><strong>Roles:\u00a0<\/strong>A collection of privileges. The role does not itself specify the type of access (read only or read\/write) to each of the managed objects. ACI provides a number of predefined roles which could be assigned but it\u2019s more likely that custom roles will need to be created to meet specific requirements.<\/p>\n<\/div>\n<\/div><\/div><\/div><\/div><\/div><\/div><div id=\"pg-284-4\"  class=\"panel-grid panel-has-style\" ><div data-tab-animation=\"none\" class=\"panel-row-style panel-row-style-for-284-4\" ><div id=\"pgc-284-4-0\"  class=\"panel-grid-cell\" ><div id=\"panel-284-4-0-0\" class=\"so-panel widget widget_sow-editor panel-first-child panel-last-child\" data-index=\"4\" ><div data-tab-animation=\"none\" class=\"panel-widget-style panel-widget-style-for-284-4-0-0\" ><div\n\t\t\t\n\t\t\tclass=\"so-widget-sow-editor so-widget-sow-editor-base\"\n\t\t\t\n\t\t>\n<div class=\"siteorigin-widget-tinymce textwidget\">\n\t<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-290\" src=\"http:\/\/www.bestpath.io\/wp-content\/uploads\/2018\/07\/Blog-05-Default-roles.png\" alt=\"\" width=\"3088\" height=\"1194\" srcset=\"https:\/\/bestpath.io\/wp-content\/uploads\/2018\/07\/Blog-05-Default-roles.png 3088w, https:\/\/bestpath.io\/wp-content\/uploads\/2018\/07\/Blog-05-Default-roles-300x116.png 300w, https:\/\/bestpath.io\/wp-content\/uploads\/2018\/07\/Blog-05-Default-roles-768x297.png 768w, https:\/\/bestpath.io\/wp-content\/uploads\/2018\/07\/Blog-05-Default-roles-1024x396.png 1024w\" sizes=\"auto, (max-width: 3088px) 100vw, 3088px\" \/><\/p>\n<p style=\"text-align: center;\"><em>In the screenshot, we can see the default roles and how a number of different privileges are assigned.<\/em><\/p>\n<p>&nbsp;<\/p>\n<p><strong>Access rights (privilege types):\u00a0<\/strong>This determines a level of access (read only or read\/write) that can be given to a role.<\/p>\n<p><strong>Security domains:\u00a0<\/strong>This is a type of tag that can be applied to a section of the MIT. The concept is best described by Cisco as \u2018an intermediate entity between tenants and users\u2019.<\/p>\n<p>These five elements above need to be bound together to control who can access what and at which privilege. A user needs to be assigned to a security-domain (default or custom) and assigned a role (default or custom) along with the role privilege type. At this point, it\u2019s worth mentioning that RBAC doesn\u2019t apply just to GUI based access but it also enforces access control to the API.<\/p>\n<p>&nbsp;<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-300\" src=\"http:\/\/www.bestpath.io\/wp-content\/uploads\/2018\/07\/RBAC.png\" alt=\"\" width=\"1138\" height=\"861\" srcset=\"https:\/\/bestpath.io\/wp-content\/uploads\/2018\/07\/RBAC.png 1138w, https:\/\/bestpath.io\/wp-content\/uploads\/2018\/07\/RBAC-300x227.png 300w, https:\/\/bestpath.io\/wp-content\/uploads\/2018\/07\/RBAC-768x581.png 768w, https:\/\/bestpath.io\/wp-content\/uploads\/2018\/07\/RBAC-1024x775.png 1024w\" sizes=\"auto, (max-width: 1138px) 100vw, 1138px\" \/><\/p>\n<p style=\"text-align: center;\"><em>In the diagram above, we can see how the security domain acts at the attachment point between the user and the tenant.<\/em><\/p>\n<p>&nbsp;<\/p>\n<\/div>\n<\/div><\/div><\/div><\/div><\/div><\/div><div id=\"pg-284-5\"  class=\"panel-grid panel-has-style\" ><div data-tab-animation=\"none\" class=\"panel-row-style panel-row-style-for-284-5\" ><div id=\"pgc-284-5-0\"  class=\"panel-grid-cell\" ><div id=\"panel-284-5-0-0\" class=\"so-panel widget widget_sow-editor panel-first-child panel-last-child\" data-index=\"5\" ><div data-tab-animation=\"none\" class=\"panel-widget-style panel-widget-style-for-284-5-0-0\" ><div\n\t\t\t\n\t\t\tclass=\"so-widget-sow-editor so-widget-sow-editor-base\"\n\t\t\t\n\t\t>\n<div class=\"siteorigin-widget-tinymce textwidget\">\n\t<h3 style=\"text-align: left;\"><strong>Considerations<\/strong><\/h3>\n<p>In current APIC software releases, security domains can only be applied at a tenant level. \u00a0There is no way to apply a security domain tag to any child class of the tenant (such as Application Profile of EPG). Therefore, if two business units shared a Tenant, both business units would have full control of each other\u2019s configuration.\u00a0It\u2019s likely that this will drive tenant design and encourage providing dedicated tenants for each business unit.<\/p>\n<p>As the APIC Security <a href=\"https:\/\/www.cisco.com\/c\/en\/us\/td\/docs\/switches\/datacenter\/aci\/apic\/sw\/2-x\/Security_config\/b_Cisco_APIC_Security_Guide.html\">Configuration Guide<\/a>\u00a0highlights, one challenge is how connectivity to bare metal severs is configured. Tenant administrators will not by default have access to the infra domain which is required to configure interfaces of leaf switches. Many organizations would be reluctant to provide users with fabric admin address for very good reasons. One way around this could be to be to blanket configure certain switch interfaces in advance ready for physical servers to be cabled to. This would prevent the tenant administrators from having to invoke support from fabric admins.<\/p>\n<p>Although this may appear to be a restriction at first, there are a number of different ways to handle the provisioning of physical connectivity via automation tasks.<\/p>\n<\/div>\n<\/div><\/div><\/div><\/div><\/div><\/div><div id=\"pg-284-6\"  class=\"panel-grid panel-has-style\" ><div data-tab-animation=\"none\" class=\"panel-row-style panel-row-style-for-284-6\" ><div id=\"pgc-284-6-0\"  class=\"panel-grid-cell\" ><div id=\"panel-284-6-0-0\" class=\"so-panel widget widget_sow-editor panel-first-child\" data-index=\"6\" ><div data-tab-animation=\"none\" class=\"panel-widget-style panel-widget-style-for-284-6-0-0\" ><div\n\t\t\t\n\t\t\tclass=\"so-widget-sow-editor so-widget-sow-editor-base\"\n\t\t\t\n\t\t>\n<div class=\"siteorigin-widget-tinymce textwidget\">\n\t<h3 style=\"text-align: left;\"><strong>External authentication<\/strong><\/h3>\n<p>Most organizations will want to incorporate an external authentication server with their RBAC solution to provide for AAA support. Cisco supports this method with the use of AV pairs configured on the authentication server e.g. Cisco ISE.\u00a0The required AV pair format is as follows:<\/p>\n<p>shell:domains =<\/p>\n<p>ACI_Security_Domain_1\/ACI_Write_Role_1|ACI_Write_Role_2|ACI_Write_Role_3\/ACI_Read_Role_1|ACI_Read_Role_2<\/p>\n<p>ACI_Security_Domain_2\/ACI_Write_Role_1\/ACI_Read_Role_1|ACI_Read_Role_2|ACI_Read_Role_3<\/p>\n<p>\"shell:domains=\" \u00a0 - \u00a0This element is required so that ACI reads the string correctly. This must always prepend the shell string.<\/p>\n<\/div>\n<\/div><\/div><\/div><div id=\"panel-284-6-0-1\" class=\"so-panel widget widget_sow-editor panel-last-child\" data-index=\"7\" ><div data-tab-animation=\"none\" class=\"panel-widget-style panel-widget-style-for-284-6-0-1\" ><div\n\t\t\t\n\t\t\tclass=\"so-widget-sow-editor so-widget-sow-editor-base\"\n\t\t\t\n\t\t>\n<div class=\"siteorigin-widget-tinymce textwidget\">\n\t<p>The first focus point for the examples below is the positioning of the \u2018\/\u2019 character as this is the separator between the security domain, write and read sections of the AV pair string. This means that any string including two consecutive forward slashes, E.g. ACI_Security_Domain_1\/\/admin, assigns the role to the security domain with read privileges only. The second focus point is the positioning of the '|' character which indicates multiple roles with the same privilege type (e.g. read only or read-write).<\/p>\n<p>Example AV pairs:<\/p>\n<p><strong>ACI_Security_Domain_1\/\/admin<\/strong>\u00a0- Grants admin read only access to the tenants in this security domain.<\/p>\n<p><strong>ACI_Security_Domain_2\/admin<\/strong>\u00a0- Grants admin write access to the tenants in this security domain.<\/p>\n<p><strong>ACI_Security_Domain_3\/vmm-admin\/fabric-admin|nw-svc-params<\/strong>\u00a0- Grants write access with the 'vmm-admin' role and read-only access to both the 'fabric-admin' role and the 'nw-svc-params' role.<\/p>\n<p>&nbsp;<\/p>\n<\/div>\n<\/div><\/div><\/div><\/div><\/div><\/div><div id=\"pg-284-7\"  class=\"panel-grid panel-has-style\" ><div data-tab-animation=\"none\" class=\"panel-row-style panel-row-style-for-284-7\" ><div id=\"pgc-284-7-0\"  class=\"panel-grid-cell\" ><div id=\"panel-284-7-0-0\" class=\"so-panel widget widget_sow-editor panel-first-child\" data-index=\"8\" ><div data-tab-animation=\"none\" class=\"panel-widget-style panel-widget-style-for-284-7-0-0\" ><div\n\t\t\t\n\t\t\tclass=\"so-widget-sow-editor so-widget-sow-editor-base\"\n\t\t\t\n\t\t>\n<div class=\"siteorigin-widget-tinymce textwidget\">\n\t<h3 style=\"text-align: left;\"><strong>Additional features<\/strong><\/h3>\n<p>ACI has one additional trick up it's sleeve to offer further flexibility for access control; a concept called 'Custom RBAC rules'. Rather than performing all access control based on security domains, Custom RBAC can provide explicit access to specific objects outside of the assigned security. Based on the earlier example, Dave Smith had been assigned to the 'engineering-domain' security domain which would have provided him access to the 'engineering' tenant. This is represented by the 'Implicit Rules'.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-298\" src=\"http:\/\/www.bestpath.io\/wp-content\/uploads\/2018\/07\/Blog-05-RBAC-rules-Implicit.png\" alt=\"\" width=\"3403\" height=\"606\" srcset=\"https:\/\/bestpath.io\/wp-content\/uploads\/2018\/07\/Blog-05-RBAC-rules-Implicit.png 3403w, https:\/\/bestpath.io\/wp-content\/uploads\/2018\/07\/Blog-05-RBAC-rules-Implicit-300x53.png 300w, https:\/\/bestpath.io\/wp-content\/uploads\/2018\/07\/Blog-05-RBAC-rules-Implicit-768x137.png 768w, https:\/\/bestpath.io\/wp-content\/uploads\/2018\/07\/Blog-05-RBAC-rules-Implicit-1024x182.png 1024w\" sizes=\"auto, (max-width: 3403px) 100vw, 3403px\" \/><\/p>\n<p>&nbsp;<\/p>\n<p>However, to provide Dave Smith with access to an object outside of his assigned security domain, an 'Explicit Rule' can be created to bind the distinguished name of an object (e.g. uni\/tn-sales). This would allow the user to access the 'Sales' tenant which would be assigned to a different security domain. Explicit rules are essentially cross security domain exceptions.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-299\" src=\"http:\/\/www.bestpath.io\/wp-content\/uploads\/2018\/07\/Blog-05-RBAC-rules-Explicit.png\" alt=\"\" width=\"3381\" height=\"461\" srcset=\"https:\/\/bestpath.io\/wp-content\/uploads\/2018\/07\/Blog-05-RBAC-rules-Explicit.png 3381w, https:\/\/bestpath.io\/wp-content\/uploads\/2018\/07\/Blog-05-RBAC-rules-Explicit-300x41.png 300w, https:\/\/bestpath.io\/wp-content\/uploads\/2018\/07\/Blog-05-RBAC-rules-Explicit-768x105.png 768w, https:\/\/bestpath.io\/wp-content\/uploads\/2018\/07\/Blog-05-RBAC-rules-Explicit-1024x140.png 1024w\" sizes=\"auto, (max-width: 3381px) 100vw, 3381px\" \/><\/p>\n<p>&nbsp;<\/p>\n<\/div>\n<\/div><\/div><\/div><div id=\"panel-284-7-0-1\" class=\"so-panel widget widget_sow-editor panel-last-child\" data-index=\"9\" ><div data-tab-animation=\"none\" class=\"panel-widget-style panel-widget-style-for-284-7-0-1\" ><div\n\t\t\t\n\t\t\tclass=\"so-widget-sow-editor so-widget-sow-editor-base\"\n\t\t\t\n\t\t>\n<div class=\"siteorigin-widget-tinymce textwidget\">\n\t<p>An interesting authentication feature that is supported is the concept of dynamically assigning roles based on time or explicit request. This could be useful in extremely security conscious environments where access control is a priority. In this case, write privileges could be assigned dynamically when a change window commences.<\/p>\n<p>Additionally, as of release 3.1, the APIC will actively throttle the number of password-based authentication requests once a certain threshold is breached. Although this doesn\u2019t sound like an issue for GUI users, this is an issue once levels of automation are increased and the number of REST calls to the API increase dramatically. The recommended solution is to use certificate-based authentication for access to the API. Not only does this mitigate the authentication throttling and improve security, it also reduces the time for automation tasks to complete. We\u2019ve seen certificate-based authentication drastically reduce the time required to provision full tenant structures via Ansible so strongly recommend this.<\/p>\n<\/div>\n<\/div><\/div><\/div><\/div><\/div><\/div><div id=\"pg-284-8\"  class=\"panel-grid panel-has-style\" ><div data-tab-animation=\"none\" class=\"panel-row-style panel-row-style-for-284-8\" ><div id=\"pgc-284-8-0\"  class=\"panel-grid-cell\" ><div id=\"panel-284-8-0-0\" class=\"so-panel widget widget_sow-editor panel-first-child panel-last-child\" data-index=\"10\" ><div data-tab-animation=\"none\" class=\"panel-widget-style panel-widget-style-for-284-8-0-0\" ><div\n\t\t\t\n\t\t\tclass=\"so-widget-sow-editor so-widget-sow-editor-base\"\n\t\t\t\n\t\t>\n<div class=\"siteorigin-widget-tinymce textwidget\">\n\t<p>In conclusion, RBAC could easily be considered as a simple task but when tenant design and automation strategies are taken into consideration, there is more to it than first meets the eye.<\/p>\n<p>BestPath.<\/p>\n<\/div>\n<\/div><\/div><\/div><\/div><\/div><\/div><\/div>","protected":false},"excerpt":{"rendered":"<p>An overview of the Role Based Access Control (RBAC) functionality available with Cisco ACI. This article covers some of the challenges found when configuring RBAC in a multi-tenancy private cloud environment.<\/p>\n","protected":false},"author":1,"featured_media":302,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[5,15,1],"tags":[],"class_list":["post-284","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-all","category-dc-networking","category-news-post"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v22.7 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Cisco ACI RBAC (Role Based Access Control) - BestPath<\/title>\n<meta name=\"description\" content=\"Welcome to our article on how Cisco ACI RBAC (Role Based Access Control) can be used to provide granular visibility and security within a Cisco ACI fabric\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/bestpath.io\/cisco-aci-rbac\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Cisco ACI RBAC (Role Based Access Control) - BestPath\" \/>\n<meta property=\"og:description\" content=\"Welcome to our article on how Cisco ACI RBAC (Role Based Access Control) can be used to provide granular visibility and security within a Cisco ACI fabric\" \/>\n<meta property=\"og:url\" content=\"https:\/\/bestpath.io\/cisco-aci-rbac\/\" \/>\n<meta property=\"og:site_name\" content=\"BestPath\" \/>\n<meta property=\"article:published_time\" content=\"2018-07-14T11:12:32+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2023-06-07T13:33:11+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/bestpath.io\/wp-content\/uploads\/2018\/07\/shutterstock_1114015298-Medium-1024x632.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1024\" \/>\n\t<meta property=\"og:image:height\" content=\"632\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"wpengine\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"wpengine\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/bestpath.io\/cisco-aci-rbac\/\",\"url\":\"https:\/\/bestpath.io\/cisco-aci-rbac\/\",\"name\":\"Cisco ACI RBAC (Role Based Access Control) - BestPath\",\"isPartOf\":{\"@id\":\"https:\/\/www.bestpath.io\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/bestpath.io\/cisco-aci-rbac\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/bestpath.io\/cisco-aci-rbac\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/bestpath.io\/wp-content\/uploads\/2018\/07\/shutterstock_1114015298-Medium.jpg\",\"datePublished\":\"2018-07-14T11:12:32+00:00\",\"dateModified\":\"2023-06-07T13:33:11+00:00\",\"author\":{\"@id\":\"https:\/\/www.bestpath.io\/#\/schema\/person\/e9dc45340d32f0c1f3bf804f768bb643\"},\"description\":\"Welcome to our article on how Cisco ACI RBAC (Role Based Access Control) can be used to provide granular visibility and security within a Cisco ACI fabric\",\"breadcrumb\":{\"@id\":\"https:\/\/bestpath.io\/cisco-aci-rbac\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/bestpath.io\/cisco-aci-rbac\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/bestpath.io\/cisco-aci-rbac\/#primaryimage\",\"url\":\"https:\/\/bestpath.io\/wp-content\/uploads\/2018\/07\/shutterstock_1114015298-Medium.jpg\",\"contentUrl\":\"https:\/\/bestpath.io\/wp-content\/uploads\/2018\/07\/shutterstock_1114015298-Medium.jpg\",\"width\":5673,\"height\":3502},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/bestpath.io\/cisco-aci-rbac\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.bestpath.io\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Cisco ACI role based access control (RBAC)\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.bestpath.io\/#website\",\"url\":\"https:\/\/www.bestpath.io\/\",\"name\":\"BestPath\",\"description\":\"Leading the way to find the best networking solutions\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.bestpath.io\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.bestpath.io\/#\/schema\/person\/e9dc45340d32f0c1f3bf804f768bb643\",\"name\":\"wpengine\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.bestpath.io\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/d8770fe9625ca7c4601f13d9d0ab86565a6dac8cd6a77bfe2ada6d83c6837870?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/d8770fe9625ca7c4601f13d9d0ab86565a6dac8cd6a77bfe2ada6d83c6837870?s=96&d=mm&r=g\",\"caption\":\"wpengine\"},\"description\":\"This is the \\\"wpengine\\\" admin user that our staff uses to gain access to your admin area to provide support and troubleshooting. It can only be accessed by a button in our secure log that auto generates a password and dumps that password after the staff member has logged in. We have taken extreme measures to ensure that our own user is not going to be misused to harm any of our clients sites.\",\"sameAs\":[\"http:\/\/wpengine.com\"],\"url\":\"https:\/\/bestpath.io\/author\/wpengine\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Cisco ACI RBAC (Role Based Access Control) - BestPath","description":"Welcome to our article on how Cisco ACI RBAC (Role Based Access Control) can be used to provide granular visibility and security within a Cisco ACI fabric","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/bestpath.io\/cisco-aci-rbac\/","og_locale":"en_US","og_type":"article","og_title":"Cisco ACI RBAC (Role Based Access Control) - BestPath","og_description":"Welcome to our article on how Cisco ACI RBAC (Role Based Access Control) can be used to provide granular visibility and security within a Cisco ACI fabric","og_url":"https:\/\/bestpath.io\/cisco-aci-rbac\/","og_site_name":"BestPath","article_published_time":"2018-07-14T11:12:32+00:00","article_modified_time":"2023-06-07T13:33:11+00:00","og_image":[{"width":1024,"height":632,"url":"https:\/\/bestpath.io\/wp-content\/uploads\/2018\/07\/shutterstock_1114015298-Medium-1024x632.jpg","type":"image\/jpeg"}],"author":"wpengine","twitter_card":"summary_large_image","twitter_misc":{"Written by":"wpengine","Est. reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/bestpath.io\/cisco-aci-rbac\/","url":"https:\/\/bestpath.io\/cisco-aci-rbac\/","name":"Cisco ACI RBAC (Role Based Access Control) - BestPath","isPartOf":{"@id":"https:\/\/www.bestpath.io\/#website"},"primaryImageOfPage":{"@id":"https:\/\/bestpath.io\/cisco-aci-rbac\/#primaryimage"},"image":{"@id":"https:\/\/bestpath.io\/cisco-aci-rbac\/#primaryimage"},"thumbnailUrl":"https:\/\/bestpath.io\/wp-content\/uploads\/2018\/07\/shutterstock_1114015298-Medium.jpg","datePublished":"2018-07-14T11:12:32+00:00","dateModified":"2023-06-07T13:33:11+00:00","author":{"@id":"https:\/\/www.bestpath.io\/#\/schema\/person\/e9dc45340d32f0c1f3bf804f768bb643"},"description":"Welcome to our article on how Cisco ACI RBAC (Role Based Access Control) can be used to provide granular visibility and security within a Cisco ACI fabric","breadcrumb":{"@id":"https:\/\/bestpath.io\/cisco-aci-rbac\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/bestpath.io\/cisco-aci-rbac\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/bestpath.io\/cisco-aci-rbac\/#primaryimage","url":"https:\/\/bestpath.io\/wp-content\/uploads\/2018\/07\/shutterstock_1114015298-Medium.jpg","contentUrl":"https:\/\/bestpath.io\/wp-content\/uploads\/2018\/07\/shutterstock_1114015298-Medium.jpg","width":5673,"height":3502},{"@type":"BreadcrumbList","@id":"https:\/\/bestpath.io\/cisco-aci-rbac\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.bestpath.io\/"},{"@type":"ListItem","position":2,"name":"Cisco ACI role based access control (RBAC)"}]},{"@type":"WebSite","@id":"https:\/\/www.bestpath.io\/#website","url":"https:\/\/www.bestpath.io\/","name":"BestPath","description":"Leading the way to find the best networking solutions","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.bestpath.io\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/www.bestpath.io\/#\/schema\/person\/e9dc45340d32f0c1f3bf804f768bb643","name":"wpengine","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.bestpath.io\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/d8770fe9625ca7c4601f13d9d0ab86565a6dac8cd6a77bfe2ada6d83c6837870?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/d8770fe9625ca7c4601f13d9d0ab86565a6dac8cd6a77bfe2ada6d83c6837870?s=96&d=mm&r=g","caption":"wpengine"},"description":"This is the \"wpengine\" admin user that our staff uses to gain access to your admin area to provide support and troubleshooting. It can only be accessed by a button in our secure log that auto generates a password and dumps that password after the staff member has logged in. We have taken extreme measures to ensure that our own user is not going to be misused to harm any of our clients sites.","sameAs":["http:\/\/wpengine.com"],"url":"https:\/\/bestpath.io\/author\/wpengine\/"}]}},"jetpack_featured_media_url":"https:\/\/bestpath.io\/wp-content\/uploads\/2018\/07\/shutterstock_1114015298-Medium.jpg","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/bestpath.io\/wp-json\/wp\/v2\/posts\/284","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/bestpath.io\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/bestpath.io\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/bestpath.io\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/bestpath.io\/wp-json\/wp\/v2\/comments?post=284"}],"version-history":[{"count":18,"href":"https:\/\/bestpath.io\/wp-json\/wp\/v2\/posts\/284\/revisions"}],"predecessor-version":[{"id":5514,"href":"https:\/\/bestpath.io\/wp-json\/wp\/v2\/posts\/284\/revisions\/5514"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/bestpath.io\/wp-json\/wp\/v2\/media\/302"}],"wp:attachment":[{"href":"https:\/\/bestpath.io\/wp-json\/wp\/v2\/media?parent=284"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/bestpath.io\/wp-json\/wp\/v2\/categories?post=284"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/bestpath.io\/wp-json\/wp\/v2\/tags?post=284"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}