<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Local ASA passwords to allow ALL show commands, no config in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/local-asa-passwords-to-allow-all-show-commands-no-config/m-p/2191557#M359403</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Assuming AAA authentication, define some users with intermediate privilege levels and assign the commands they can run to that level, e.g.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; username readonly password SomeSecret privilege 2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;followed by a tedious number of privilege commands for each of the keywords "show ?" expands to:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;privilege show level 2 mode exec command aaa-server&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;privilege show level 2 mode exec command xlate&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyone knowing a more consise way would be welcome.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-- Jim Leinweber, WI State Lab of Hygiene&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 27 Mar 2013 22:33:15 GMT</pubDate>
    <dc:creator>James Leinweber</dc:creator>
    <dc:date>2013-03-27T22:33:15Z</dc:date>
    <item>
      <title>Local ASA passwords to allow ALL show commands, no config</title>
      <link>https://community.cisco.com/t5/network-security/local-asa-passwords-to-allow-all-show-commands-no-config/m-p/2191556#M359402</link>
      <description>&lt;P&gt;Hi there&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Currently have an ASA 5545. &lt;SPAN style="font-size: 10pt;"&gt;What I want to do is allow our support team to perform ALL show commands (up to and including show run) but not enable them to perform ANY configuration changes on the devices (not get into config t). This is to allow them to check ARP tables, routing protocol status, etc&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can anyone advise the syntax to do this? i don't have access to the ASA at the moment and haven't been able to figure it out in IOS, i'm assuming its not too hard...&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 01:20:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/local-asa-passwords-to-allow-all-show-commands-no-config/m-p/2191556#M359402</guid>
      <dc:creator>pheavens85</dc:creator>
      <dc:date>2019-03-12T01:20:17Z</dc:date>
    </item>
    <item>
      <title>Local ASA passwords to allow ALL show commands, no config</title>
      <link>https://community.cisco.com/t5/network-security/local-asa-passwords-to-allow-all-show-commands-no-config/m-p/2191557#M359403</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Assuming AAA authentication, define some users with intermediate privilege levels and assign the commands they can run to that level, e.g.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; username readonly password SomeSecret privilege 2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;followed by a tedious number of privilege commands for each of the keywords "show ?" expands to:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;privilege show level 2 mode exec command aaa-server&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;privilege show level 2 mode exec command xlate&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyone knowing a more consise way would be welcome.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-- Jim Leinweber, WI State Lab of Hygiene&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Mar 2013 22:33:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/local-asa-passwords-to-allow-all-show-commands-no-config/m-p/2191557#M359403</guid>
      <dc:creator>James Leinweber</dc:creator>
      <dc:date>2013-03-27T22:33:15Z</dc:date>
    </item>
  </channel>
</rss>

