<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Username with privilege level 15 bypass enable in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/username-with-privilege-level-15-bypass-enable/m-p/1633581#M257943</link>
    <description>&lt;P&gt;Hi experts,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I guess I never really understand the authentication process on Cisco routers and devices lol. Anyway I want users with privilege level 15 to be put in the enable mode right away after login without having to type in "enable" command and enable password. Users with other privilege levels will still be put in the EXEC mode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;AAA has to be enabled because I'm using it for 802.1x as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The privilege level eventually will be assigned by Radius server but right now the user is created locally on the switch. Right now I have:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;aaa new-model&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;username admin privilege 15 secret 5 $1$2bdl$VIp53G4/zpo4f9aHh.t5v0&lt;BR /&gt;username cisco secret 5 $1$NGdD$ehTUzwappJFMxgA7tM/YW.&lt;BR /&gt;!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;line vty 0 5&lt;BR /&gt; access-class 100 in&lt;BR /&gt; exec-timeout 30 0&lt;BR /&gt; logging synchronous&lt;BR /&gt; transport input ssh&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000;"&gt;And it's not working lol. No matter I log in with "admin" or "cisco" I'm put in EXEC mode... What do I have to do to achieve this?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000;"&gt;Thanks!&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 00:45:33 GMT</pubDate>
    <dc:creator>Difan Zhao</dc:creator>
    <dc:date>2019-03-11T00:45:33Z</dc:date>
    <item>
      <title>Username with privilege level 15 bypass enable</title>
      <link>https://community.cisco.com/t5/network-access-control/username-with-privilege-level-15-bypass-enable/m-p/1633581#M257943</link>
      <description>&lt;P&gt;Hi experts,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I guess I never really understand the authentication process on Cisco routers and devices lol. Anyway I want users with privilege level 15 to be put in the enable mode right away after login without having to type in "enable" command and enable password. Users with other privilege levels will still be put in the EXEC mode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;AAA has to be enabled because I'm using it for 802.1x as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The privilege level eventually will be assigned by Radius server but right now the user is created locally on the switch. Right now I have:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;aaa new-model&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;username admin privilege 15 secret 5 $1$2bdl$VIp53G4/zpo4f9aHh.t5v0&lt;BR /&gt;username cisco secret 5 $1$NGdD$ehTUzwappJFMxgA7tM/YW.&lt;BR /&gt;!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;line vty 0 5&lt;BR /&gt; access-class 100 in&lt;BR /&gt; exec-timeout 30 0&lt;BR /&gt; logging synchronous&lt;BR /&gt; transport input ssh&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000;"&gt;And it's not working lol. No matter I log in with "admin" or "cisco" I'm put in EXEC mode... What do I have to do to achieve this?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000;"&gt;Thanks!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 00:45:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/username-with-privilege-level-15-bypass-enable/m-p/1633581#M257943</guid>
      <dc:creator>Difan Zhao</dc:creator>
      <dc:date>2019-03-11T00:45:33Z</dc:date>
    </item>
    <item>
      <title>Re: Username with privilege level 15 bypass enable</title>
      <link>https://community.cisco.com/t5/network-access-control/username-with-privilege-level-15-bypass-enable/m-p/1633582#M257947</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;On the cisco device issue the below listed command&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;aaa authorization exec default group radius local &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;On the radius server if its ACS or IAS &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;set the service type attribute like this&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;services-type=Administrative&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;doing this, user will be start landing in privelege exec mode #&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Jatin&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Do rate helpful posts-&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 Jan 2011 17:39:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/username-with-privilege-level-15-bypass-enable/m-p/1633582#M257947</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2011-01-26T17:39:07Z</dc:date>
    </item>
    <item>
      <title>Re: Username with privilege level 15 bypass enable</title>
      <link>https://community.cisco.com/t5/network-access-control/username-with-privilege-level-15-bypass-enable/m-p/1633583#M257952</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The with default keyword authorization will get applied on all the lines i.e. &lt;SPAN style=": ; line-height: 115%; color: #000000; font-size: 10pt; sans-serif&amp;quot;: ; font-family: &amp;quot; , &amp;quot;: ; Arial&amp;quot;: ; "&gt;CONSOLE, VTY, AUX.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style=": ; line-height: 115%; color: #000000; font-size: 10pt; sans-serif&amp;quot;: ; font-family: &amp;quot; , &amp;quot;: ; Arial&amp;quot;: ; "&gt;In case you want it for users who are trying to login to via ssh or telnet use the following:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="line-height: 115%; font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; font-size: 10pt;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;STRONG style="mso-bidi-font-weight: normal; : ; color: #000000; font-size: 12pt; font-family: Calibri; "&gt;EXEC AUTHORIZATION&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;SPAN style="font-family: Calibri; color: #000000; font-size: 12pt;"&gt;Router&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;SPAN style=": ; line-height: 115%; color: #000000; font-size: 10pt; sans-serif&amp;quot;: ; font-family: &amp;quot; , &amp;quot;: ; Arial&amp;quot;: ; "&gt;router(config)#aaa authorization exec TEL GRoup radius local&lt;BR /&gt;router(config)#line vty 0 15&lt;BR /&gt;router(config-line)#authorization exec TEL&lt;BR style="mso-special-character: line-break;" /&gt;&lt;BR style="mso-special-character: line-break;" /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;SPAN style="font-family: Calibri; color: #000000; font-size: 12pt;"&gt;ACS&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;SPAN style="font-family: Calibri; color: #000000; font-size: 12pt;"&gt;Interface configuration&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;SPAN style="font-family: Calibri; color: #000000; font-size: 12pt;"&gt;Check&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;user &amp;amp; group for cisco av-pair.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; "&gt;&lt;SPAN style="font-family: Calibri;"&gt;User setup &lt;/SPAN&gt;&lt;SPAN style="mso-symbol-font-family: Wingdings; mso-char-type: symbol; mso-ascii-font-family: Calibri; mso-hansi-theme-font: minor-latin; font-family: Wingdings; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; "&gt;à&lt;/SPAN&gt;&lt;SPAN style="font-family: Calibri;"&gt; cisco ios/pix 6.x radius attributes &lt;/SPAN&gt;&lt;SPAN style="mso-symbol-font-family: Wingdings; mso-char-type: symbol; mso-ascii-font-family: Calibri; mso-hansi-theme-font: minor-latin; font-family: Wingdings; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; "&gt;à&lt;/SPAN&gt;&lt;SPAN style="font-family: Calibri;"&gt;cisco av-pair [ shell:priv-lvl=15]&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;SPAN style="font-family: Calibri; color: #000000; font-size: 12pt;"&gt;OR&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; "&gt;&lt;SPAN style="font-family: Calibri;"&gt;Group setup &lt;/SPAN&gt;&lt;SPAN style="mso-symbol-font-family: Wingdings; mso-char-type: symbol; mso-ascii-font-family: Calibri; mso-hansi-theme-font: minor-latin; font-family: Wingdings; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; "&gt;à&lt;/SPAN&gt;&lt;SPAN style="font-family: Calibri;"&gt; ios/pix 6.x radius attributes &lt;/SPAN&gt;&lt;SPAN style="mso-symbol-font-family: Wingdings; mso-char-type: symbol; mso-ascii-font-family: Calibri; mso-hansi-theme-font: minor-latin; font-family: Wingdings; mso-ascii-theme-font: minor-latin; mso-hansi-font-family: Calibri; "&gt;à&lt;/SPAN&gt;&lt;SPAN style="font-family: Calibri;"&gt; shell:priv-lvl=15&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;SPAN style="font-family: Calibri; color: #000000; font-size: 12pt;"&gt;In case of radius if exec authorization is enabled&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;and if have not specified any privilege level in the ACS server. Then user will fall under the privilege level 1 and if enable authentication is enabled&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;or enable password is defined&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;on the router then we can go to enable mode by typing en or en &lt;PRIV-LVL&gt;&lt;/PRIV-LVL&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;Regards,&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;Anisha&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;P.S.: please mark this thread as resolved if you think your query is answered.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Jan 2011 15:03:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/username-with-privilege-level-15-bypass-enable/m-p/1633583#M257952</guid>
      <dc:creator>andamani</dc:creator>
      <dc:date>2011-01-27T15:03:49Z</dc:date>
    </item>
    <item>
      <title>Re: Username with privilege level 15 bypass enable</title>
      <link>https://community.cisco.com/t5/network-access-control/username-with-privilege-level-15-bypass-enable/m-p/1633584#M257956</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks guys!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Jan 2011 23:17:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/username-with-privilege-level-15-bypass-enable/m-p/1633584#M257956</guid>
      <dc:creator>Difan Zhao</dc:creator>
      <dc:date>2011-01-27T23:17:41Z</dc:date>
    </item>
  </channel>
</rss>

