<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Read-only access to switches in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/read-only-access-to-switches/m-p/2142873#M133438</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;you need to change the exec privelege level for the commands based on your need&lt;/P&gt;&lt;P&gt;and then assign the user to the privilege level needed using the command&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;R(config)#username &amp;lt; username&amp;gt; privilege &amp;lt; 0 -15&amp;gt;&amp;nbsp; password &lt;PASSWORD&gt;&lt;/PASSWORD&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;how to change the priv level of a command&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;R(config)#privilege exec level &amp;lt;0 15 &amp;gt; &lt;COMMAND&gt;&lt;/COMMAND&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But this is a headache man.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;---------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;Please make sure to rate correct answers&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 14 Mar 2013 13:41:01 GMT</pubDate>
    <dc:creator>maldehne</dc:creator>
    <dc:date>2013-03-14T13:41:01Z</dc:date>
    <item>
      <title>Read-only access to switches</title>
      <link>https://community.cisco.com/t5/network-access-control/read-only-access-to-switches/m-p/2142868#M133297</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm trying to figure out what is the best way to limite access to Cisco switch. I'm using AAA and radius for authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My goal is to create a user that will have only "enable" access (all the show commands, etc..). I would like to deny access to "configure terminal" and some other commands like "reload".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is the best way to do that ? I'm reading about privileges and it doesn't seem to be powerful. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I read a little about Role-based access and views but before starting to configure and test this, I would like to have your hint on this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Wed, 13 Mar 2019 00:41:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/read-only-access-to-switches/m-p/2142868#M133297</guid>
      <dc:creator>Vinny</dc:creator>
      <dc:date>2019-03-13T00:41:36Z</dc:date>
    </item>
    <item>
      <title>Read-only access to switches</title>
      <link>https://community.cisco.com/t5/network-access-control/read-only-access-to-switches/m-p/2142869#M133319</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The best way to do this is with a TACACS+ server where you can utilize "command shells" where certain commands are allowed while others not. Radius does not have this functionality and you can only push a "privilege-level" attribute. Thus, if you want to restrict commands then you will have to define those locally on every switch. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if this makes sense and/or if you have more quesions. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Thank you for rating!&lt;/EM&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Mar 2013 04:38:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/read-only-access-to-switches/m-p/2142869#M133319</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2013-03-14T04:38:56Z</dc:date>
    </item>
    <item>
      <title>Read-only access to switches</title>
      <link>https://community.cisco.com/t5/network-access-control/read-only-access-to-switches/m-p/2142870#M133343</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You are saying that I can do it locally on switches, what is the best way for that ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Mar 2013 13:02:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/read-only-access-to-switches/m-p/2142870#M133343</guid>
      <dc:creator>Vinny</dc:creator>
      <dc:date>2013-03-14T13:02:33Z</dc:date>
    </item>
    <item>
      <title>Read-only access to switches</title>
      <link>https://community.cisco.com/t5/network-access-control/read-only-access-to-switches/m-p/2142871#M133382</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can do that locally but the best to do is through Tacacs+ command authorization sets.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check the following links:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/partner/products/sw/secursw/ps2086/products_configuration_example09186a00808d9138.shtml"&gt;http://www.cisco.com/en/US/partner/products/sw/secursw/ps2086/products_configuration_example09186a00808d9138.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/partner/products/ps9911/products_configuration_example09186a0080bc8514.shtml"&gt;http://www.cisco.com/en/US/partner/products/ps9911/products_configuration_example09186a0080bc8514.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;Please make sure to rate correct answers&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Mar 2013 13:16:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/read-only-access-to-switches/m-p/2142871#M133382</guid>
      <dc:creator>maldehne</dc:creator>
      <dc:date>2013-03-14T13:16:36Z</dc:date>
    </item>
    <item>
      <title>Read-only access to switches</title>
      <link>https://community.cisco.com/t5/network-access-control/read-only-access-to-switches/m-p/2142872#M133408</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I dont' have a tatacs+ server so I need to do it locally.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Mar 2013 13:19:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/read-only-access-to-switches/m-p/2142872#M133408</guid>
      <dc:creator>Vinny</dc:creator>
      <dc:date>2013-03-14T13:19:54Z</dc:date>
    </item>
    <item>
      <title>Read-only access to switches</title>
      <link>https://community.cisco.com/t5/network-access-control/read-only-access-to-switches/m-p/2142873#M133438</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;you need to change the exec privelege level for the commands based on your need&lt;/P&gt;&lt;P&gt;and then assign the user to the privilege level needed using the command&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;R(config)#username &amp;lt; username&amp;gt; privilege &amp;lt; 0 -15&amp;gt;&amp;nbsp; password &lt;PASSWORD&gt;&lt;/PASSWORD&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;how to change the priv level of a command&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;R(config)#privilege exec level &amp;lt;0 15 &amp;gt; &lt;COMMAND&gt;&lt;/COMMAND&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But this is a headache man.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;---------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;Please make sure to rate correct answers&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Mar 2013 13:41:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/read-only-access-to-switches/m-p/2142873#M133438</guid>
      <dc:creator>maldehne</dc:creator>
      <dc:date>2013-03-14T13:41:01Z</dc:date>
    </item>
  </channel>
</rss>

