Body
** Work in Progress: Article may be updated as OpM migration proceeds **
Description
OpManager access has 3 prerequisites: each new user needs their privileged account to be added to an OpM group in OKTA, a dedicated local account created in OpManager, and a UNLV network connection on-campus or via VPN. The steps to provision the first 2 access requirements will be listed below.
OKTA Provision Instructions
-
Login to the OKTA Admin console
-
Access the OKTA Group
-
Open the 'Groups' tab
-
Open the corresponding OpManager OKTA group for the user's team (i.e. 'UD - OpManager Network Engineering' for NDE users)
-
If the group does not exist, reach out to Tammy Phan to have it created. The format is 'UD - OpManager (unit name)' with OpM access provisioned and OC edit access enabled.
-
Add the user
-
Click on 'Assign People'
-
Add the user's Privileged account (firstname.lastname@unlv.edu)
OpManager Account Creation Instructions
-
Login to OpManager
-
Make sure 'All Probes' is selected after login
-
Open User Management page
-
Navigate to Settings > General Settings > User Management
-
Add User
-
Click on 'Add User'
-
Select 'Role'
-
There are currently two roles for non-admins: Monitoring Only & Elevated Monitoring
-
Elevated Monitoring: for NDE users specifically, contains additional read-only access to NCM and other node details
-
Monitoring Only: for all other users and teams, also only read-only
-
Administrator role currently only available for Operations Center members
-
Select 'User Type'
-
Set to 'Local Authentication'
-
Set 'Username'
-
Input entire UNLVMail address
-
Set 'Email ID'
-
Input entire UNLVMail address
-
Set 'Password'
-
Password does not matter as OKTA will be verifying login instead
-
Use random password generator for this entry
-
Click Next
-
Specify User Scope (scope will vary depending on user role)
-
For Elevated Monitoring users
-
Enable Monitor (All Devices)
-
Enable Netflow (All Devices/Groups)
-
Enable NCM
-
Enable OpUtils
-
Enable DPI
-
For Monitoring Only users
-
Enable Monitor (All Devices)
-
Enable Netflow (All Devices/Groups)
-
Specify Probe
-
Choose 'All Probes'
-
Click 'Save'
Account Troubleshooting
** WIP: will expand later **