<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Getting the Switch Web Interface to run at a lower privilege in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/getting-the-switch-web-interface-to-run-at-a-lower-privilege/m-p/961570#M376179</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;    What I really want is to allow my techs to use the Web interface on our 2960 and 3560 Switches to help troubleshoot issues.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;    I have it working throug Tacacs now but it order to login you have to have privilege of 15.  I do not want to give my techs privelege 15 so I am trying to see if you can access the web console at a lower privelege.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;    Preferrably I would like the techs to see the pretty interface but not be able to make permanent changes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;    Is this even possible?  I tried doing this by setting the "ip http authentication aaa command-authorization 5 HTTPOnly".  I then set the "aaa authorization command" for HTTPOnly to 5.  This did not seem to allow a users with a Tacacs privilege of 5 to login.  On the debug it is still asking to for level 15 privelege.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;    Any help would be apreciated.&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 22:49:10 GMT</pubDate>
    <dc:creator>blittrell</dc:creator>
    <dc:date>2019-03-10T22:49:10Z</dc:date>
    <item>
      <title>Getting the Switch Web Interface to run at a lower privilege</title>
      <link>https://community.cisco.com/t5/network-access-control/getting-the-switch-web-interface-to-run-at-a-lower-privilege/m-p/961570#M376179</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;    What I really want is to allow my techs to use the Web interface on our 2960 and 3560 Switches to help troubleshoot issues.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;    I have it working throug Tacacs now but it order to login you have to have privilege of 15.  I do not want to give my techs privelege 15 so I am trying to see if you can access the web console at a lower privelege.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;    Preferrably I would like the techs to see the pretty interface but not be able to make permanent changes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;    Is this even possible?  I tried doing this by setting the "ip http authentication aaa command-authorization 5 HTTPOnly".  I then set the "aaa authorization command" for HTTPOnly to 5.  This did not seem to allow a users with a Tacacs privilege of 5 to login.  On the debug it is still asking to for level 15 privelege.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;    Any help would be apreciated.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 22:49:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/getting-the-switch-web-interface-to-run-at-a-lower-privilege/m-p/961570#M376179</guid>
      <dc:creator>blittrell</dc:creator>
      <dc:date>2019-03-10T22:49:10Z</dc:date>
    </item>
    <item>
      <title>Re: Getting the Switch Web Interface to run at a lower privilege</title>
      <link>https://community.cisco.com/t5/network-access-control/getting-the-switch-web-interface-to-run-at-a-lower-privilege/m-p/961571#M376248</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I don't think that is possible. We need to have priv 15 for http accesses. It is possible with ASA asdm but not sure about SDM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Will check it and let you know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;~JG&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 May 2008 14:48:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/getting-the-switch-web-interface-to-run-at-a-lower-privilege/m-p/961571#M376248</guid>
      <dc:creator>Jagdeep Gambhir</dc:creator>
      <dc:date>2008-05-01T14:48:30Z</dc:date>
    </item>
    <item>
      <title>Re: Getting the Switch Web Interface to run at a lower privilege</title>
      <link>https://community.cisco.com/t5/network-access-control/getting-the-switch-web-interface-to-run-at-a-lower-privilege/m-p/961572#M376283</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for checking:)  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Was also wondering what the command-authorization is for, if not to set the privelege level for accessing the SDM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 May 2008 15:07:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/getting-the-switch-web-interface-to-run-at-a-lower-privilege/m-p/961572#M376283</guid>
      <dc:creator>blittrell</dc:creator>
      <dc:date>2008-05-01T15:07:51Z</dc:date>
    </item>
  </channel>
</rss>

