<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic local username database, restrict user access to cli in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/local-username-database-restrict-user-access-to-cli/m-p/1976799#M202133</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think there is an easy way&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;define the user with privilege 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That should do&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Users can still login but they cant access/manage the router&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 20 Oct 2012 14:09:03 GMT</pubDate>
    <dc:creator>bejoybkn1</dc:creator>
    <dc:date>2012-10-20T14:09:03Z</dc:date>
    <item>
      <title>local username database, restrict user access to cli</title>
      <link>https://community.cisco.com/t5/network-access-control/local-username-database-restrict-user-access-to-cli/m-p/1976792#M202120</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am interesting if it is possible to restrict cli access to users from local database, they should be working only for EasyVPN ?&lt;/P&gt;&lt;P&gt;Is it possible to do this without exsternal db ?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 02:14:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/local-username-database-restrict-user-access-to-cli/m-p/1976792#M202120</guid>
      <dc:creator>ngtransge</dc:creator>
      <dc:date>2019-03-11T02:14:05Z</dc:date>
    </item>
    <item>
      <title>local username database, restrict user access to cli</title>
      <link>https://community.cisco.com/t5/network-access-control/local-username-database-restrict-user-access-to-cli/m-p/1976793#M202122</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Could you elaborate your question?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What device are we using for authenticating users like version, model, platform?&lt;/P&gt;&lt;P&gt;Which CLI access are you refering here...CLI access to your switches/routers/firewalls?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Jatin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Jun 2012 13:53:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/local-username-database-restrict-user-access-to-cli/m-p/1976793#M202122</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2012-06-25T13:53:19Z</dc:date>
    </item>
    <item>
      <title>local username database, restrict user access to cli</title>
      <link>https://community.cisco.com/t5/network-access-control/local-username-database-restrict-user-access-to-cli/m-p/1976794#M202124</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Jatin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am using 3945E Router as Easy VPN Server, with 15.1 IOS. On router I have bunch on usernames for VPN authentication, I want to restrict Router management access for them(ssh,telnet, http and so on). &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Jun 2012 16:21:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/local-username-database-restrict-user-access-to-cli/m-p/1976794#M202124</guid>
      <dc:creator>ngtransge</dc:creator>
      <dc:date>2012-06-25T16:21:55Z</dc:date>
    </item>
    <item>
      <title>local username database, restrict user access to cli</title>
      <link>https://community.cisco.com/t5/network-access-control/local-username-database-restrict-user-access-to-cli/m-p/1976795#M202126</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can setup local command authorization for the same.&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/tech/tk59/technologies_tech_note09186a00800949d5.shtml" rel="nofollow"&gt;http://www.cisco.com/en/US/tech/tk59/technologies_tech_note09186a00800949d5.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Jatin&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do rate helpful posts-&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Jun 2012 20:09:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/local-username-database-restrict-user-access-to-cli/m-p/1976795#M202126</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2012-06-25T20:09:47Z</dc:date>
    </item>
    <item>
      <title>local username database, restrict user access to cli</title>
      <link>https://community.cisco.com/t5/network-access-control/local-username-database-restrict-user-access-to-cli/m-p/1976796#M202128</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;how can I use these command ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Jun 2012 21:19:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/local-username-database-restrict-user-access-to-cli/m-p/1976796#M202128</guid>
      <dc:creator>ngtransge</dc:creator>
      <dc:date>2012-06-25T21:19:00Z</dc:date>
    </item>
    <item>
      <title>local username database, restrict user access to cli</title>
      <link>https://community.cisco.com/t5/network-access-control/local-username-database-restrict-user-access-to-cli/m-p/1976797#M202130</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #ffffff; font-family: Arial, verdana, sans-serif; font-size: 12px;"&gt;Early I saw one example when it was done with aaa atribute list, and it was working, but on 3945E it is not working.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;Here is example :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;aaa new-model&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;!&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;aaa authentication login ezvpn_users local&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;aaa authorization network ezvpn_users local&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;!&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;aaa attribute list ezvpn_users&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;attribute type service-type noopt service shell mandatory&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;!&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;username user1 password 0 superpasword&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;username user1 aaa attribute list ezvpn_users&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Do you have some&amp;nbsp; information about it ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Jun 2012 07:09:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/local-username-database-restrict-user-access-to-cli/m-p/1976797#M202130</guid>
      <dc:creator>ngtransge</dc:creator>
      <dc:date>2012-06-27T07:09:01Z</dc:date>
    </item>
    <item>
      <title>local username database, restrict user access to cli</title>
      <link>https://community.cisco.com/t5/network-access-control/local-username-database-restrict-user-access-to-cli/m-p/1976798#M202132</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;try&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"aaa authorization exec default local"&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Oct 2012 13:12:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/local-username-database-restrict-user-access-to-cli/m-p/1976798#M202132</guid>
      <dc:creator>Archil Sokhadze</dc:creator>
      <dc:date>2012-10-19T13:12:07Z</dc:date>
    </item>
    <item>
      <title>local username database, restrict user access to cli</title>
      <link>https://community.cisco.com/t5/network-access-control/local-username-database-restrict-user-access-to-cli/m-p/1976799#M202133</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think there is an easy way&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;define the user with privilege 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That should do&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Users can still login but they cant access/manage the router&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 20 Oct 2012 14:09:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/local-username-database-restrict-user-access-to-cli/m-p/1976799#M202133</guid>
      <dc:creator>bejoybkn1</dc:creator>
      <dc:date>2012-10-20T14:09:03Z</dc:date>
    </item>
  </channel>
</rss>

