<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PIX Privilege Levels in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-privilege-levels/m-p/561884#M499352</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;"""When commands have privilege levels set, and users have privilege levels set, then the two are compared to determine if a given user can execute a given command.""" If the user's privilege level is lower than the privilege level of the command, the user is prevented from executing the command.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;here i feel you have configured privilege level for account ,however you have n't specified the commands which should correspond to priv. level 2.So,pix has nothing to compare and that's why you are able to execute all of the commands.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 14 Jul 2006 21:01:08 GMT</pubDate>
    <dc:creator>suschoud</dc:creator>
    <dc:date>2006-07-14T21:01:08Z</dc:date>
    <item>
      <title>PIX Privilege Levels</title>
      <link>https://community.cisco.com/t5/network-security/pix-privilege-levels/m-p/561882#M499349</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have configured a username with privilege level 2 on my PIX but have not defined any commands for Level2.&lt;/P&gt;&lt;P&gt;Even then i observe that when i logon with those credentials iam able to go to the configure mode and by an large execute all the commands.&lt;/P&gt;&lt;P&gt;What is causing this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My PIX Ver- 6.3(3)&lt;/P&gt;&lt;P&gt;====================&lt;/P&gt;&lt;P&gt;username monitor password xxx encrypted privilege 2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PIX-525# show curpriv&lt;/P&gt;&lt;P&gt;Username : monitor&lt;/P&gt;&lt;P&gt;Current privilege level : 2&lt;/P&gt;&lt;P&gt;Current Mode/s : P_PRIV&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 09:02:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-privilege-levels/m-p/561882#M499349</guid>
      <dc:creator>rpsrekhi3</dc:creator>
      <dc:date>2020-02-21T09:02:55Z</dc:date>
    </item>
    <item>
      <title>Re: PIX Privilege Levels</title>
      <link>https://community.cisco.com/t5/network-security/pix-privilege-levels/m-p/561883#M499351</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;sounds like you have enabled authentication but not authorisation. try:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authorization command LOCAL &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;privilege cmd level 2 mode exec command show&lt;/P&gt;&lt;P&gt;privilege cmd level 2 mode exec command quit&lt;/P&gt;&lt;P&gt;privilege show level 2 mode exec command interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;etc&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Jul 2006 20:37:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-privilege-levels/m-p/561883#M499351</guid>
      <dc:creator>grant.maynard</dc:creator>
      <dc:date>2006-07-14T20:37:28Z</dc:date>
    </item>
    <item>
      <title>Re: PIX Privilege Levels</title>
      <link>https://community.cisco.com/t5/network-security/pix-privilege-levels/m-p/561884#M499352</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;"""When commands have privilege levels set, and users have privilege levels set, then the two are compared to determine if a given user can execute a given command.""" If the user's privilege level is lower than the privilege level of the command, the user is prevented from executing the command.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;here i feel you have configured privilege level for account ,however you have n't specified the commands which should correspond to priv. level 2.So,pix has nothing to compare and that's why you are able to execute all of the commands.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Jul 2006 21:01:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-privilege-levels/m-p/561884#M499352</guid>
      <dc:creator>suschoud</dc:creator>
      <dc:date>2006-07-14T21:01:08Z</dc:date>
    </item>
  </channel>
</rss>

