Check for Required IAM Permissions
GigaVUE‑FM allows you to validate whether policy attached to the GigaVUE-FM using "EC2 Instance Role" or "Access Credential" has the required IAM permissions and notifies the users about the missing permissions. You can check permissions while creating Monitoring Domain and deploying GigaVUE Fabric Components using GigaVUE-FM, by clicking the Check Permissions button on the Monitoring Domain Configuration page and AWS Fabric Launch Configuration page. The GigaVUE‑FM displays the minimum required IAM permissions.
The following are the prerequisites that are required to deploy GigaVUE Cloud Suite for AWS:
- IAM permissions - Checks whether the minimum required permissions are granted for the instance where the GigaVUE‑FM is deployed. Refer to Permissions and Privileges (AWS) for more detailed information on how to configure the required permissions in AWS.
- Access to public cloud end points - Check for access to the AWS cloud end point APIs.
- Subscription to the GigaVUE Cloud Suite for AWS- Before deploying the solution, you must subscribe to the GigaVUE Cloud Suite components from the AWS marketplace. It checks whether the required components are subscribed in the marketplace. Refer to Subscribe to GigaVUE Products for more detailed information on how to subscribe to the Gigamon Products.
- Security Group - Checks whether the required ports are configured in the security group. For more information on the security groups, seeSecurity Group Network Security Groups
Note: Security group rules validation does not validate prefix List and user groups. For a successful validation, the ports and CIDR range should be updated in the Security Group.
After you press the Check Permissions button, GigaVUE‑FM will verify the minimum required permissions. Any missing permissions will be highlighted with the respective message against the permission in a dialog box. You can use the displayed IAM Policy JSON as a reference and update the policy that is attached to the GigaVUE‑FM.
Refer to the following sections for more detailed information: