A-30
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 7.2
OL-29168-01
AppendixA System Architecture
CLI
CLI
The CLI provides the sensor user interface for all dire ct node access such as Telnet, SSH, and serial
interface. You configure the sensor applications with the CLI. Direct access to the underlying OS is
allowed through the service role. This section describes the IPS CLI, and contains the following topics:
User Roles, pageA-30
Service Account, page A-31

User Roles

Caution
You should carefully consider whether you want to create a service account. The service account
provides shell access to the system, which makes the system vulnerable. However, you can use the
service account to create a password if the administrator password is lost. Analyze your situation to
decide if you want a service account existing on the system.
There are four user roles:
Viewer—Can view configuration and events, but cannot modify any configuration data except their
user passwords.
Operator—Can view everything and can modify the following options:
Signature tuning (priority, disable or enable)
Virtual sensor definition
Managed routers
Their user passwords
Administrator—Can view everything and can modify all options that operators can modify in
addition to the following:
Sensor addressing configuration
List of hosts allowed to connect as configuration or viewing agents
Assignment of physical sensing interfaces
Enable or disable control of physical interfaces
Add and delete users and passwords
Generate new SSH host keys and server certificates
Service—Only one user with service privileges can exist on a sensor. The service user cannot log in
to the IDM or the IME. The service user logs in to a bash shell rather than the CLI.
The service role is a special role that allows you to bypass the CLI if needed. Only one service
account is allowed. You should only create an account with the service role for troubleshooting
purposes. Only a user with administrator privileges can edit the service account.
When you log in to the service account, you receive the following warning:
************************ WARNING *************************************************
UNAUTHORIZED ACCESS TO THIS NETWORK DEVICE IS PROHIBITED.
This account is intended to be used for support and troubleshooting purposes only.
Unauthorized modifications are not supported and will require this device to be
re-imaged to guarantee proper operation.
**********************************************************************************