<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic AAA question.... in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/aaa-question/m-p/1732112#M256405</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Nilesh,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if you have just one router and two users you can cerate just this two users with limited access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;conf t&lt;/P&gt;&lt;P&gt;username user1 privilege 1 password cisco&lt;/P&gt;&lt;P&gt;username user 2 privilege 5 password cisco&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;privilege exec level 5 show running-config&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;user1 can log into the device, bat cannot do anything. I really don't understand for waht reason you want him then to login to the device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;user2 can log in and execute the show running-config command&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;when the two user log in by telnet don't forget to add this command to your vty line&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;vty 0 4&lt;/P&gt;&lt;P&gt;login local&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;alex&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 04 Aug 2011 17:18:10 GMT</pubDate>
    <dc:creator>alex.dersch</dc:creator>
    <dc:date>2011-08-04T17:18:10Z</dc:date>
    <item>
      <title>AAA question....</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-question/m-p/1732111#M256364</link>
      <description>&lt;P style="margin: 0in; margin-bottom: .0001pt;"&gt;&lt;EM&gt;Hello Security Experts,&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0in; margin-bottom: .0001pt;"&gt;&lt;EM&gt; &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0in; margin-bottom: .0001pt;"&gt;&lt;EM&gt;I need your help for AAA configuration.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0in; margin-bottom: .0001pt;"&gt;&lt;EM&gt;I'm Planning to implement AAA security on my Router...Could you please anyone tell me how to implement &amp;amp; what is a requirement &amp;amp; also pls. provide me document for my reference.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0in; margin-bottom: .0001pt;"&gt;&lt;EM&gt; &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0in; margin-bottom: .0001pt;"&gt;&lt;EM&gt;I have 2 users they want to give limited login access on my Cisco Router.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0in; margin-bottom: .0001pt;"&gt;&lt;EM&gt; &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0in; margin-bottom: .0001pt;"&gt;&lt;STRONG&gt;&lt;EM style="text-decoration: underline; "&gt;1st Question: -&lt;/EM&gt;&lt;/STRONG&gt;&lt;EM&gt; 1 users can able to login in Router but he should not enter into privilege mode &amp;amp; not able to execute any command.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0in; margin-bottom: .0001pt;"&gt;&lt;STRONG&gt;&lt;EM style="text-decoration: underline; "&gt;2nd question: -&lt;/EM&gt;&lt;/STRONG&gt;&lt;EM&gt; Another user can able to logging any mode but he should not able to change any running-configuration &amp;amp; startup-configuration.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0in; margin-bottom: .0001pt;"&gt;&lt;EM&gt; &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0in; margin-bottom: .0001pt;"&gt;&lt;EM&gt;Please advise me &amp;amp; pls. provide me AAA related document becoz. In future any new requirement so I can able to do myself &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0in; margin-bottom: .0001pt;"&gt;&lt;EM&gt; &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0in; margin-bottom: .0001pt;"&gt;&lt;EM&gt; &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0in; margin-bottom: .0001pt;"&gt;&lt;EM&gt;HTH&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0in; margin-bottom: .0001pt;"&gt;&lt;EM&gt;Nilesh.&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 01:16:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-question/m-p/1732111#M256364</guid>
      <dc:creator>bhornilesh</dc:creator>
      <dc:date>2019-03-11T01:16:24Z</dc:date>
    </item>
    <item>
      <title>AAA question....</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-question/m-p/1732112#M256405</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Nilesh,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if you have just one router and two users you can cerate just this two users with limited access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;conf t&lt;/P&gt;&lt;P&gt;username user1 privilege 1 password cisco&lt;/P&gt;&lt;P&gt;username user 2 privilege 5 password cisco&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;privilege exec level 5 show running-config&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;user1 can log into the device, bat cannot do anything. I really don't understand for waht reason you want him then to login to the device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;user2 can log in and execute the show running-config command&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;when the two user log in by telnet don't forget to add this command to your vty line&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;vty 0 4&lt;/P&gt;&lt;P&gt;login local&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;alex&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Aug 2011 17:18:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-question/m-p/1732112#M256405</guid>
      <dc:creator>alex.dersch</dc:creator>
      <dc:date>2011-08-04T17:18:10Z</dc:date>
    </item>
  </channel>
</rss>

