<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASDM Access and local username/PW in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/asdm-access-and-local-username-pw/m-p/1014617#M385537</link>
    <description>&lt;P&gt;Ok, I happened upon this today and thought it was a bit weird. We have a pair of ASA5520 as our primary firewalls. &lt;/P&gt;&lt;P&gt;We are using EasyVPN,and the usernames authenticate via the local username / PW configured on the firewall. All of these usernames have Privilege 0, however, these usernames are able to log into the firewall via SSH, AND when I use one of them to log into ASDM, they can go in and make config changes. I don't like that.I'm sure you can see why... How do I make it so that only my level 15 priv username can get logged in via ASDM? I've looked into AAA command authorization, but I don't see how that would apply to ASDM access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Firewall setup:&lt;/P&gt;&lt;P&gt;aaa authentication http console LOCAL&lt;/P&gt;&lt;P&gt;aaa authentication ssh console LOCAL&lt;/P&gt;&lt;P&gt;aaa authentication enable console LOCAL&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;username user password password priv 15&lt;/P&gt;&lt;P&gt;username user1 password password1 priv 0&lt;/P&gt;&lt;P&gt;username user2 password password2 priv 0&lt;/P&gt;&lt;P&gt;username user3 password password3 priv 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 22:50:10 GMT</pubDate>
    <dc:creator>rtjensen4</dc:creator>
    <dc:date>2019-03-10T22:50:10Z</dc:date>
    <item>
      <title>ASDM Access and local username/PW</title>
      <link>https://community.cisco.com/t5/network-access-control/asdm-access-and-local-username-pw/m-p/1014617#M385537</link>
      <description>&lt;P&gt;Ok, I happened upon this today and thought it was a bit weird. We have a pair of ASA5520 as our primary firewalls. &lt;/P&gt;&lt;P&gt;We are using EasyVPN,and the usernames authenticate via the local username / PW configured on the firewall. All of these usernames have Privilege 0, however, these usernames are able to log into the firewall via SSH, AND when I use one of them to log into ASDM, they can go in and make config changes. I don't like that.I'm sure you can see why... How do I make it so that only my level 15 priv username can get logged in via ASDM? I've looked into AAA command authorization, but I don't see how that would apply to ASDM access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Firewall setup:&lt;/P&gt;&lt;P&gt;aaa authentication http console LOCAL&lt;/P&gt;&lt;P&gt;aaa authentication ssh console LOCAL&lt;/P&gt;&lt;P&gt;aaa authentication enable console LOCAL&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;username user password password priv 15&lt;/P&gt;&lt;P&gt;username user1 password password1 priv 0&lt;/P&gt;&lt;P&gt;username user2 password password2 priv 0&lt;/P&gt;&lt;P&gt;username user3 password password3 priv 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 22:50:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/asdm-access-and-local-username-pw/m-p/1014617#M385537</guid>
      <dc:creator>rtjensen4</dc:creator>
      <dc:date>2019-03-10T22:50:10Z</dc:date>
    </item>
    <item>
      <title>Re: ASDM Access and local username/PW</title>
      <link>https://community.cisco.com/t5/network-access-control/asdm-access-and-local-username-pw/m-p/1014618#M385589</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To achieve this you need to enable authorization. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authorization command LOCAL&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if you have any questions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;~JG&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do rate helpful posts&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 May 2008 01:50:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/asdm-access-and-local-username-pw/m-p/1014618#M385589</guid>
      <dc:creator>Jagdeep Gambhir</dc:creator>
      <dc:date>2008-05-09T01:50:39Z</dc:date>
    </item>
  </channel>
</rss>

