<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA - Restrict 'config t' for user &amp; allow all show commands in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-restrict-config-t-for-user-allow-all-show-commands/m-p/1281257#M834658</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Most likely you are missing aaa authorization command.. see bellow link and links within.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://forum.cisco.com/eforum/servlet/NetProf?page=netprof&amp;amp;forum=Security&amp;amp;topic=Firewalling&amp;amp;topicID=.ee6e1fa&amp;amp;fromOutline=true&amp;amp;CommCmd=MB?cmd=display_location&amp;amp;location=.2cc2c575/4" target="_blank"&gt;http://forum.cisco.com/eforum/servlet/NetProf?page=netprof&amp;amp;forum=Security&amp;amp;topic=Firewalling&amp;amp;topicID=.ee6e1fa&amp;amp;fromOutline=true&amp;amp;CommCmd=MB?cmd=display_location&amp;amp;location=.2cc2c575/4&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 16 Jun 2009 20:13:24 GMT</pubDate>
    <dc:creator>JORGE RODRIGUEZ</dc:creator>
    <dc:date>2009-06-16T20:13:24Z</dc:date>
    <item>
      <title>ASA - Restrict 'config t' for user &amp; allow all show commands</title>
      <link>https://community.cisco.com/t5/network-security/asa-restrict-config-t-for-user-allow-all-show-commands/m-p/1281256#M834649</link>
      <description>&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like to restrict 'config t' to user privilege level 5. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Currently when I do 'sh run all privlege level all | i command configure'&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can see the below &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;privilege cmd level 15 mode exec command configure&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;which I believe means only level 15 can do a config t. But even when the enable level is '5', I can enter config t and have all the change entries available. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are not using TACAS+. The complete AAA configuration in ASA is only the following&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication ssh console LOCAL&lt;/P&gt;&lt;P&gt;aaa authentication serial console LOCAL&lt;/P&gt;&lt;P&gt;aaa authentication http console LOCAL&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, if I like to permit all show commands at a certain level, do I have to explicitly permit every show command to level 5 or is there any wild card i.e. to permit all 'show' commands within user/privileged mode to a particular level. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please assist. &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 15:44:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-restrict-config-t-for-user-allow-all-show-commands/m-p/1281256#M834649</guid>
      <dc:creator>tech_trac</dc:creator>
      <dc:date>2019-03-11T15:44:03Z</dc:date>
    </item>
    <item>
      <title>Re: ASA - Restrict 'config t' for user &amp; allow all show commands</title>
      <link>https://community.cisco.com/t5/network-security/asa-restrict-config-t-for-user-allow-all-show-commands/m-p/1281257#M834658</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Most likely you are missing aaa authorization command.. see bellow link and links within.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://forum.cisco.com/eforum/servlet/NetProf?page=netprof&amp;amp;forum=Security&amp;amp;topic=Firewalling&amp;amp;topicID=.ee6e1fa&amp;amp;fromOutline=true&amp;amp;CommCmd=MB?cmd=display_location&amp;amp;location=.2cc2c575/4" target="_blank"&gt;http://forum.cisco.com/eforum/servlet/NetProf?page=netprof&amp;amp;forum=Security&amp;amp;topic=Firewalling&amp;amp;topicID=.ee6e1fa&amp;amp;fromOutline=true&amp;amp;CommCmd=MB?cmd=display_location&amp;amp;location=.2cc2c575/4&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Jun 2009 20:13:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-restrict-config-t-for-user-allow-all-show-commands/m-p/1281257#M834658</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2009-06-16T20:13:24Z</dc:date>
    </item>
    <item>
      <title>Re: ASA - Restrict 'config t' for user &amp; allow all show commands</title>
      <link>https://community.cisco.com/t5/network-security/asa-restrict-config-t-for-user-allow-all-show-commands/m-p/1281258#M834666</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks. It worked. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Still looking for answer to the other question. When I enable the user at level 5, all show commands are restricted. And when I add 'privilege show level 5 mode exec command interface', only then the user can do show interface. Does it mean I would have to add all the show commands if I would like to permit 'show' to user level 5. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Jun 2009 04:51:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-restrict-config-t-for-user-allow-all-show-commands/m-p/1281258#M834666</guid>
      <dc:creator>tech_trac</dc:creator>
      <dc:date>2009-06-17T04:51:33Z</dc:date>
    </item>
    <item>
      <title>Re: ASA - Restrict 'config t' for user &amp; allow all show commands</title>
      <link>https://community.cisco.com/t5/network-security/asa-restrict-config-t-for-user-allow-all-show-commands/m-p/1281259#M834686</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You have to define what commmands level 5 is authorized for.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;for example&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if you want priv level 5 to be able to do who running-config then you  tell asa:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;B&gt;privilege show level 5 mode exec command running-config&lt;/B&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the same appies for interface as you have done.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;B&gt;privilege show level 5 mode exec command interface&lt;/B&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you will have to go over this link for more thorought details &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/mgaccess.html#wp1070306" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/mgaccess.html#wp1070306&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Jun 2009 19:04:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-restrict-config-t-for-user-allow-all-show-commands/m-p/1281259#M834686</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2009-06-17T19:04:54Z</dc:date>
    </item>
  </channel>
</rss>

