Skip to main content

OS-specific Access Level

Last updated on March 20, 2025

The following table summarizes the minimum privilege level account type needed for collection and whether the exact set of commands permitted on the account can be controlled by TACACS server for each supported firewall platform.

VendorSoftware/OS VersionDevice TypeMinimum privilege level required (Account Type/Role)TACACS Support
A10Thunder, ax3030, virtual A10a10_acos_sshPrivilege level 0 (read-only user)Yes (Role-based, commands cannot be defined)
AristaEOS 4.14, 4.15, 4.18arista_eos_sshPrivilege level 15Yes
ArubaArubaOS, Version 7.4.1.11aruba_switch_sshUser role: Read-onlyYes (Role-based)
ArubaEdgeConnect SD-WAN (former Silverpeak)silver_peak_orchestrator_api, silver_peak_edgeconnect_sshUser role: Admin or MonitorYes (Role-based)
AviTested on 8.1.5 Avi versionavi_controller_sshSpecial role was createdYes
Bluecoatbluecoat_sshNo
CheckpointGaia R67+checkpoint_sshUser with adminRole or role with 'Expert mode' feature enabled in R/W modeYes (Role-based command control)
CiscoIOS/IOS-XEcisco_ios_ssh, cisco_ios_xe_sshPrivilege level 5Yes
CiscoIOS-XRcisco_ios_xr_sshPrivilege level 15Yes
CiscoASAcisco_asa_sshPrivilege level 5Yes
CiscoNX-OScisco_nxos_sshPrivilege level 15Yes
CiscoACIcisco_apic_ssh, cisco_nxos_aci_sshAdmin role with read privilege type and security domain allYes
CiscoMeraki MX 18.107meraki_api-No
CitrixNetscaler 12.0netscaler_sshSuperuserYes
CumulusTested on 3.5 and 4.0 versionscumulus_sshPrivilege level 0 (collector commands access)Yes
F5BIGIP 9.4.8-12.1.2f5_sshUser with Guest role (read-only access)Yes (Role-based)
ForcepointForcepointforcepoint_https_api, forcepoint_sshAPI: Operator role (All Domains). SSH: Predefined root userNo
FortinetFortiGate-3600C v5.2.4,build0688,150811 (GA)fortinet_sshUser with access to the diagnose command access, super_admin profileYes
HPComwarehp_comware_sshPrivilege level 1Yes
HPProvisionhp_provision_sshPrivilege level 1Yes
JuniperSession Smart Router (former 128T SD-WAN)128t_conductor, 128t_routerUser access level (config-read capability) for all routers.No
Palo-AltoPAN-OS 9.0panos_sshDevicereaderNo
Palo-AltoPAN-OS 8.0panos_sshSuperuserNo
Palo-AltoPrisma SD-WAN (former Cloudgenix)prisma_sdwan_ssh, prisma_sdwan_apiUser role: read-onlyNo
RiverbedRiOSriverbed_steelhead_ssh-Yes
VCenter6., 7., 8.*vcenter_apiRead-onlyNo
VersaVersa SD-WANversa_director_ssh, versa_flexvnf_sshVersa supports RBAC when logging into director node, however since we collect from each node separately via SSH, the role Versa-Role attribute is ignored.Yes