Community discussions

MikroTik App
 
moose999
just joined
Topic Author
Posts: 6
Joined: Fri Sep 11, 2015 8:46 pm

Granular User Levels

Tue Jan 16, 2018 12:37 pm

Hi,

I am aware I can control access to services (web, winbox, api, etc.) and rights (read, write, sensitive, etc.) but how can I control access to features (/ip firewall nat for example)?

Many thanks,
Justin
 
User avatar
sebastia
Forum Guru
Forum Guru
Posts: 1782
Joined: Tue Oct 12, 2010 3:23 am
Location: Antwerp, BE

Re: Granular User Levels

Tue Jan 16, 2018 12:40 pm

To my knowledge, such filtering is currently not supported.
 
User avatar
normis
MikroTik Support
MikroTik Support
Posts: 26930
Joined: Fri May 28, 2004 11:04 am
Location: Riga, Latvia
Contact:

Re: Granular User Levels

Tue Jan 16, 2018 1:04 pm

You can use the API to make your own GUI tool, or you can use Design Skin mode to modify Webfig to hide unnecessary menus.
This is more cosmetic though, not very secure.
 
moose999
just joined
Topic Author
Posts: 6
Joined: Fri Sep 11, 2015 8:46 pm

Re: Granular User Levels

Tue Jan 16, 2018 1:46 pm

Thank you so much, that works really well!

You mention that its "not very secure". Is this because a user could craft manual HTTP requests and send them to Webfig? If they had another RouterOS to play with, determining these requests would be very easy (Chrome developer tools / Wireshark) I think?

Many thanks again,
Justin.
 
User avatar
normis
MikroTik Support
MikroTik Support
Posts: 26930
Joined: Fri May 28, 2004 11:04 am
Location: Riga, Latvia
Contact:

Re: Granular User Levels

Tue Jan 16, 2018 1:52 pm

Guessing the correct menu URL still works. This is just for convenience of the user, not for actually protecting the hidden menu from the user.