<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Change privilege levels in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/change-privilege-levels/m-p/318494#M433661</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As I understand it, the implementation of privilege levels concerning show running-config is that there is a restriction that if you do not have the ability to change a certain parameter, that parameterr will not show up when you do show running-config. I believe that this reflects a security decision that if you do not have the ability to change it, it might compromise security if you could see it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would suggest that you test this by configuring certain things that a person at privilege level 7 can change in configuration. Then have that person do show run and see if these things do not show up.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 02 Sep 2004 17:13:58 GMT</pubDate>
    <dc:creator>Richard Burts</dc:creator>
    <dc:date>2004-09-02T17:13:58Z</dc:date>
    <item>
      <title>Change privilege levels</title>
      <link>https://community.cisco.com/t5/network-access-control/change-privilege-levels/m-p/318493#M433658</link>
      <description>&lt;P&gt;Hi. I'm using an IAS Server. There I've defined two policies: One to authorizate a users with Shell:Priv-lvl=7 and other with Shell:Priv-lvl=15. I have this configuration at the router: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aaa authentication login CONTROL group radius local&lt;/P&gt;&lt;P&gt;aaa authorization exec CONTROL group radius local&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;username alejandra privilege 15 password 0 perdomo&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;radius-server host 192.168.207.10 auth-port 1812 acct-port 1813&lt;/P&gt;&lt;P&gt;radius-server retransmit 3&lt;/P&gt;&lt;P&gt;radius-server key 1234&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;privilege exec level 7 ping&lt;/P&gt;&lt;P&gt;privilege exec level 7 clear counters&lt;/P&gt;&lt;P&gt;privilege exec level 7 show running-config&lt;/P&gt;&lt;P&gt;line vty 0 4&lt;/P&gt;&lt;P&gt; authorization exec CONTROL&lt;/P&gt;&lt;P&gt; login authentication CONTROL&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As you can see I've defined the "Show Running-config" command with privilege 7. When I access to the router with privilege 7, I would be able to apply this command, I can see it, but when I run it, there is not a complete answer with all router's configuration. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I searched on &lt;A class="jive-link-custom" href="http://www.Cisco.com" target="_blank"&gt;www.Cisco.com&lt;/A&gt; and I found examples to make what I want, but they don't work properly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you help me??? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 20:46:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/change-privilege-levels/m-p/318493#M433658</guid>
      <dc:creator>AP270778</dc:creator>
      <dc:date>2019-03-10T20:46:52Z</dc:date>
    </item>
    <item>
      <title>Re: Change privilege levels</title>
      <link>https://community.cisco.com/t5/network-access-control/change-privilege-levels/m-p/318494#M433661</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As I understand it, the implementation of privilege levels concerning show running-config is that there is a restriction that if you do not have the ability to change a certain parameter, that parameterr will not show up when you do show running-config. I believe that this reflects a security decision that if you do not have the ability to change it, it might compromise security if you could see it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would suggest that you test this by configuring certain things that a person at privilege level 7 can change in configuration. Then have that person do show run and see if these things do not show up.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Sep 2004 17:13:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/change-privilege-levels/m-p/318494#M433661</guid>
      <dc:creator>Richard Burts</dc:creator>
      <dc:date>2004-09-02T17:13:58Z</dc:date>
    </item>
  </channel>
</rss>

