<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AAA - exec priv levels in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/aaa-exec-priv-levels/m-p/358571#M433398</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi SubAa,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The 'privilege exec level 15 show' command is incorrect, it shouldn't be there. Remvoe it and it will work. I have added the correction to the errata list.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Yusuf&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 14 Oct 2004 02:10:54 GMT</pubDate>
    <dc:creator>yusuff</dc:creator>
    <dc:date>2004-10-14T02:10:54Z</dc:date>
    <item>
      <title>AAA - exec priv levels</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-exec-priv-levels/m-p/358570#M433397</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The followings are from the Yusuf bible. I think some of you had read and configured all that labs, so I really hope it's just a simple question for you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, In Chap. 1 / Section 7.1:&lt;/P&gt;&lt;P&gt;-------------------------------------------------&lt;/P&gt;&lt;P&gt;"Configure two users: (user1) - with priv lvl 10, and user2 w/ priv. level 15. Configure such that user1 is able to sun the command show run only, and user2 is able to run all commands."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The solution is (- per the configs on cd):&lt;/P&gt;&lt;P&gt;privilege exec level 10 show run &lt;/P&gt;&lt;P&gt;privilege exec level 15 show &lt;/P&gt;&lt;P&gt;-------------------------------------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Prevously I thought that if you move the show command with any argument (here show run) to a specific level, than you move 'show run' and all show commands too to that specific level. In the abovementioned two lines, the second command overwrites the previous statement. It is true, that the show run command moves to priv lvl 10, but the next one moves all the show commands back to level 15.&lt;/P&gt;&lt;P&gt;Please correct me if I am wrong.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In fact I am far from being happy with that. My real question is:&lt;/P&gt;&lt;P&gt;Is it possible at all to solve the task with local command authorization? (If yes, how? :D)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maybe I|m just blind to see something in the config - that's not the first time... &lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for your help!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Bests,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SubAa&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 20:51:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-exec-priv-levels/m-p/358570#M433397</guid>
      <dc:creator>subaa</dc:creator>
      <dc:date>2019-03-10T20:51:03Z</dc:date>
    </item>
    <item>
      <title>Re: AAA - exec priv levels</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-exec-priv-levels/m-p/358571#M433398</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi SubAa,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The 'privilege exec level 15 show' command is incorrect, it shouldn't be there. Remvoe it and it will work. I have added the correction to the errata list.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Yusuf&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Oct 2004 02:10:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-exec-priv-levels/m-p/358571#M433398</guid>
      <dc:creator>yusuff</dc:creator>
      <dc:date>2004-10-14T02:10:54Z</dc:date>
    </item>
  </channel>
</rss>

