Trellix Intrusion Prevention System supports creation of multiple user accounts for the Sensor. Each of these user accounts is created for various functions, that is, different roles are associated with these user accounts. The role of a user determines the CLI commands he or she is able to access.
The following Sensor user roles are supported:
Admin– Access to all commandsRead and Write– Access to all commands, except the ones available only to the administratorRead Only– Access to all show commandsUpdater– Access to update Sensor images and signature filesMaintainer– Access to update Sensor images, signature files, and also adding a Sensor to a specific Manager
Note
The debug commands can be accessed by admins or users with read and write access.
You can authenticate users by using either TACACS+ or RADIUS servers. For a TACACS+ user to obtain granular access control, authorization should be enabled at the Sensor. If not, Admin access is given to the user. The role should be assigned in the TACACS+ server configuration. If no role is configured in the TACACS+ server, Admin access is given. If a role other than the allowed roles is assigned, Read-Only access is given. Users authenticated by RADIUS server are assigned the Admin role by default. Role based user logins cannot be created through the RADIUS server.
The following is an example of the TACACS+ server configuration file:
user=user1 {
................
................
service = intrushell {
role= “RO-Access”
}
}
Note
In case of RADIUS configuration, the role is assigned as
Adminby default.
The allowed strings to be given in the TACACS+ configuration file are the following:
“Updater”
“Maintainer”
“RO-Access”
“RW-Access”
“Admin-Access”
Note
Trellix recommends either TACACS+/RADIUS users or local users on the Sensor are configured. If both are required, ensure that users with the same name are not present in the Sensor and the TACACS+/RADIUS servers.