<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic add a local user to ASA 5512-x in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/add-a-local-user-to-asa-5512-x/m-p/2351597#M271421</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Thanks for you reply James, I am using ASDM, I just clicked 'ASDM Defined User Roles Setup' and it created 3 users 'Admin, ReadOnly and Monitor Only with privilege levels 15, 5 and 3 respectively'&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 17 Jan 2014 08:28:32 GMT</pubDate>
    <dc:creator>LionKin1984</dc:creator>
    <dc:date>2014-01-17T08:28:32Z</dc:date>
    <item>
      <title>add a local user to ASA 5512-x</title>
      <link>https://community.cisco.com/t5/network-security/add-a-local-user-to-asa-5512-x/m-p/2351593#M271413</link>
      <description>&lt;P&gt;Hello people&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am trying to add a local user to our newly purchased ASA firewall 5512-x.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we do not have a Radius or AAA server&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want to add a user who has 'view only' access level on the firewall, can I just add this new user without needing to bother with AAA?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 03:31:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/add-a-local-user-to-asa-5512-x/m-p/2351593#M271413</guid>
      <dc:creator>LionKin1984</dc:creator>
      <dc:date>2019-03-12T03:31:05Z</dc:date>
    </item>
    <item>
      <title>add a local user to ASA 5512-x</title>
      <link>https://community.cisco.com/t5/network-security/add-a-local-user-to-asa-5512-x/m-p/2351594#M271415</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Interesting question, for me atleast. I don't think that with the very default configurations you will be able to actually separate what which user can do since if you use the &lt;STRONG&gt;"enable"&lt;/STRONG&gt; password the user gains full access to all commands.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I personally don't handle much of the AAA side of our ASA management. Therefore I have never had to handle the LOCAL AAA settings on the ASA and making sure that certain user can only done specific things.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I took a quick look before posting and it seemed to me that by default the commands on the ASA are set so that very few commands are allowed for Privilege level 0 and rest are at Privilege 15 which is basically the highest level and to which you get to with the &lt;STRONG&gt;"enable"&lt;/STRONG&gt; password.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To have the ASA define which commands are allowed for the user you will need some AAA configurations on the ASA, the LOCAL username configurations with specific privilege levels and modified privilege levels for the commands that you want to allow for the specific user accounts with their specific privilege level.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you can specify the type of things this user should see then I could try to create a AAA configuration for you for this purpose. Would be good practise for myself since in our environments theres usually a separate AAA server involved.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Jan 2014 11:43:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/add-a-local-user-to-asa-5512-x/m-p/2351594#M271415</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2014-01-16T11:43:10Z</dc:date>
    </item>
    <item>
      <title>add a local user to ASA 5512-x</title>
      <link>https://community.cisco.com/t5/network-security/add-a-local-user-to-asa-5512-x/m-p/2351595#M271418</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Jouni&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your post&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Apparently you can let ASDM setup commands with the respective privilege levels by clicking 'set ASDM Defined User Roles' in Users/AAA session on ASDM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want to create a user with 'view only' access level&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;cheers&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Jan 2014 11:58:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/add-a-local-user-to-asa-5512-x/m-p/2351595#M271418</guid>
      <dc:creator>LionKin1984</dc:creator>
      <dc:date>2014-01-16T11:58:23Z</dc:date>
    </item>
    <item>
      <title>add a local user to ASA 5512-x</title>
      <link>https://community.cisco.com/t5/network-security/add-a-local-user-to-asa-5512-x/m-p/2351596#M271420</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Setting up locally authenticated users involves commands like:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;user-identity default-domain LOCAL&lt;/P&gt;&lt;P&gt;aaa authentication ssh console LOCAL &lt;/P&gt;&lt;P&gt;aaa authentication enable console LOCAL &lt;/P&gt;&lt;P&gt;aaa authorization command LOCAL &lt;/P&gt;&lt;P&gt;username sysadmin password XXXXX encrypted privilege 15&lt;/P&gt;&lt;P&gt;username readonly password YYYYY encrypted privilege 2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, by default hardly any commands are available at privilege 1 and all of them are available at privilege 15, so you might need a whole platoon of "privilege .. level 2 mode ..." commands to effect your will.&amp;nbsp; There may be less tedious ways of accomplishing this that I'm unfamiliar with.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-- Jim Leinweber, WI State Lab of Hygiene&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Jan 2014 17:02:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/add-a-local-user-to-asa-5512-x/m-p/2351596#M271420</guid>
      <dc:creator>James Leinweber</dc:creator>
      <dc:date>2014-01-16T17:02:45Z</dc:date>
    </item>
    <item>
      <title>add a local user to ASA 5512-x</title>
      <link>https://community.cisco.com/t5/network-security/add-a-local-user-to-asa-5512-x/m-p/2351597#M271421</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Thanks for you reply James, I am using ASDM, I just clicked 'ASDM Defined User Roles Setup' and it created 3 users 'Admin, ReadOnly and Monitor Only with privilege levels 15, 5 and 3 respectively'&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Jan 2014 08:28:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/add-a-local-user-to-asa-5512-x/m-p/2351597#M271421</guid>
      <dc:creator>LionKin1984</dc:creator>
      <dc:date>2014-01-17T08:28:32Z</dc:date>
    </item>
  </channel>
</rss>

