<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: privilege interface shutdown in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/privilege-interface-shutdown/m-p/511812#M426636</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Looks like you can move commands down to level 0, and here's where it says so:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/software/ios121/121cgcr/secur_r/srprt5/srdpass.htm#wp1017782" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/software/ios121/121cgcr/secur_r/srprt5/srdpass.htm#wp1017782&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;'You can use level 0 to specify a subset of commands for specific users or lines. For example, you can allow user "guest" to use only the show users and exit commands.'&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There's another passage in the same link that talks about how Level 0 commands don't automatically get allowed for higher levels:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;'There are five commands associated with privilege level 0: disable, enable, exit, help, and logout. If you configure AAA authorization for a privilege level greater than 0, these five commands will not be included.'&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So maybe that's the issue - that your level 1 user isn't inheriting level 0 command privileges because they don't pass from level 0 to higher levels.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Mason&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 22 Aug 2006 20:16:57 GMT</pubDate>
    <dc:creator>mbrown</dc:creator>
    <dc:date>2006-08-22T20:16:57Z</dc:date>
    <item>
      <title>privilege interface shutdown</title>
      <link>https://community.cisco.com/t5/network-access-control/privilege-interface-shutdown/m-p/511810#M426631</link>
      <description>&lt;P&gt;Kindly help me to configure lower privilege user should be able to shutdown the fast ethernnet inteface of the switches in my LAN. &lt;/P&gt;&lt;P&gt;I have configure Level 1 user. who has given accesses to show interface through privilege command. Now i would like give him interface shutdown option.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;below the configuration already in my switch. but the user is unable to shutdwon the interface.&lt;/P&gt;&lt;P&gt;===================================&lt;/P&gt;&lt;P&gt;switch95#sh run | includ privi&lt;/P&gt;&lt;P&gt;* are authorized access and the level of privilege you  *&lt;/P&gt;&lt;P&gt;privilege configure level 0 interface&lt;/P&gt;&lt;P&gt;privilege configure level 0 interface all shutdown&lt;/P&gt;&lt;P&gt;privilege exec level 0 ping&lt;/P&gt;&lt;P&gt;privilege exec level 0 traceroute&lt;/P&gt;&lt;P&gt;privilege exec level 0 show vlan&lt;/P&gt;&lt;P&gt;privilege exec level 0 show interface&lt;/P&gt;&lt;P&gt;privilege exec level 0 configure terminal&lt;/P&gt;&lt;P&gt;========================================&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 21:42:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/privilege-interface-shutdown/m-p/511810#M426631</guid>
      <dc:creator>tirumalababu.e</dc:creator>
      <dc:date>2019-03-10T21:42:56Z</dc:date>
    </item>
    <item>
      <title>Re: privilege interface shutdown</title>
      <link>https://community.cisco.com/t5/network-access-control/privilege-interface-shutdown/m-p/511811#M426635</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you move commands down to level 0?  I've always used 1 through 15, and moved commands down from 15 to something like level 3.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Mason&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Aug 2006 19:59:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/privilege-interface-shutdown/m-p/511811#M426635</guid>
      <dc:creator>mbrown</dc:creator>
      <dc:date>2006-08-22T19:59:22Z</dc:date>
    </item>
    <item>
      <title>Re: privilege interface shutdown</title>
      <link>https://community.cisco.com/t5/network-access-control/privilege-interface-shutdown/m-p/511812#M426636</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Looks like you can move commands down to level 0, and here's where it says so:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/software/ios121/121cgcr/secur_r/srprt5/srdpass.htm#wp1017782" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/software/ios121/121cgcr/secur_r/srprt5/srdpass.htm#wp1017782&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;'You can use level 0 to specify a subset of commands for specific users or lines. For example, you can allow user "guest" to use only the show users and exit commands.'&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There's another passage in the same link that talks about how Level 0 commands don't automatically get allowed for higher levels:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;'There are five commands associated with privilege level 0: disable, enable, exit, help, and logout. If you configure AAA authorization for a privilege level greater than 0, these five commands will not be included.'&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So maybe that's the issue - that your level 1 user isn't inheriting level 0 command privileges because they don't pass from level 0 to higher levels.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Mason&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Aug 2006 20:16:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/privilege-interface-shutdown/m-p/511812#M426636</guid>
      <dc:creator>mbrown</dc:creator>
      <dc:date>2006-08-22T20:16:57Z</dc:date>
    </item>
    <item>
      <title>Re: privilege interface shutdown</title>
      <link>https://community.cisco.com/t5/network-access-control/privilege-interface-shutdown/m-p/511813#M426637</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Humm the priv level 0 isn't supposed to even permit login, I agree with a previous post that you should use privilege 1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have tried that in several customers with considerable sucess.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Aug 2006 14:24:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/privilege-interface-shutdown/m-p/511813#M426637</guid>
      <dc:creator>fausto-oliveira</dc:creator>
      <dc:date>2006-08-23T14:24:07Z</dc:date>
    </item>
    <item>
      <title>Re: privilege interface shutdown</title>
      <link>https://community.cisco.com/t5/network-access-control/privilege-interface-shutdown/m-p/4101271#M561126</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can't put this command:&lt;/P&gt;&lt;PRE&gt;privilege configure level 5 interface all shutdown&lt;/PRE&gt;&lt;P&gt;Thank you very much.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jun 2020 05:34:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/privilege-interface-shutdown/m-p/4101271#M561126</guid>
      <dc:creator>ปลาวาฬทราย RMUTT CPE IX</dc:creator>
      <dc:date>2020-06-11T05:34:12Z</dc:date>
    </item>
    <item>
      <title>Re: privilege interface shutdown</title>
      <link>https://community.cisco.com/t5/network-access-control/privilege-interface-shutdown/m-p/4102680#M561184</link>
      <description>What is the HW/SW version of the device. If you logged in via privilege level 15 user.</description>
      <pubDate>Sat, 13 Jun 2020 14:45:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/privilege-interface-shutdown/m-p/4102680#M561184</guid>
      <dc:creator>poongarg</dc:creator>
      <dc:date>2020-06-13T14:45:53Z</dc:date>
    </item>
    <item>
      <title>Re: privilege interface shutdown</title>
      <link>https://community.cisco.com/t5/network-access-control/privilege-interface-shutdown/m-p/4103195#M561213</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;WS-C3650-48TD/IOS-XE Version 03.06.08.E&lt;/P&gt;&lt;P&gt;and could nexus do this?&lt;/P&gt;&lt;P&gt;Thank you very much.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jun 2020 09:34:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/privilege-interface-shutdown/m-p/4103195#M561213</guid>
      <dc:creator>ปลาวาฬทราย RMUTT CPE IX</dc:creator>
      <dc:date>2020-06-15T09:34:52Z</dc:date>
    </item>
  </channel>
</rss>

