<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA Read only User in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-read-only-user/m-p/1202023#M877650</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That was it.  Thanks!  Just to make sure, this ASA is also authenticating users for VPN connections by pointing to the domain.  This should not impact those users correct?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks so much!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 20 Jan 2009 20:51:40 GMT</pubDate>
    <dc:creator>angel-moon</dc:creator>
    <dc:date>2009-01-20T20:51:40Z</dc:date>
    <item>
      <title>ASA Read only User</title>
      <link>https://community.cisco.com/t5/network-security/asa-read-only-user/m-p/1202017#M877643</link>
      <description>&lt;P&gt;Hello Everyone,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can someon tell me the command for createing a user on an ASA 5500 running 7.2(3) that can only view the config but not make any changes?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance!   All replies rated&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 14:37:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-read-only-user/m-p/1202017#M877643</guid>
      <dc:creator>angel-moon</dc:creator>
      <dc:date>2019-03-11T14:37:23Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Read only User</title>
      <link>https://community.cisco.com/t5/network-security/asa-read-only-user/m-p/1202018#M877644</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can use privilege level 5, this will allow to enable mode but it will &lt;B&gt;not give config t&lt;/B&gt; access,  nor clear xlates or any clear commands, it can however  issue &lt;B&gt;show &lt;/B&gt; and its subcommands  including &lt;B&gt;show run&lt;/B&gt; , same applies when using asdm.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;create user in asa local database&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;asa(config)#username &lt;NAME&gt; password &lt;PASSWORD&gt; priviledge 5&lt;/PASSWORD&gt;&lt;/NAME&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;enable AAA to use ASA local user database&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;asa(config)#aaa authentication telnet console LOCAL&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;asa&amp;gt; en&lt;/P&gt;&lt;P&gt;Password: *******&lt;/P&gt;&lt;P&gt;asa#config t&lt;/P&gt;&lt;P&gt;             ^&lt;/P&gt;&lt;P&gt;ERROR: % Invalid input detected at '^' marker.&lt;/P&gt;&lt;P&gt;ERROR: Command authorization failed&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;asa#clear xlate&lt;/P&gt;&lt;P&gt;ERROR: % Invalid input detected at '^' marker.&lt;/P&gt;&lt;P&gt;ERROR: Command authorization failed&lt;/P&gt;&lt;P&gt;asa# &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Jan 2009 05:15:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-read-only-user/m-p/1202018#M877644</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2009-01-15T05:15:22Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Read only User</title>
      <link>https://community.cisco.com/t5/network-security/asa-read-only-user/m-p/1202019#M877645</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks.  I am not sure if access by SSH makes a difference but the user is using SSH and SSH is configured to authenticate to the local database but the user can still get to config t.  I am running 7.2 if that makes a difference.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Jan 2009 23:21:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-read-only-user/m-p/1202019#M877645</guid>
      <dc:creator>angel-moon</dc:creator>
      <dc:date>2009-01-19T23:21:35Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Read only User</title>
      <link>https://community.cisco.com/t5/network-security/asa-read-only-user/m-p/1202020#M877646</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Add bellow statement , have you defined priviledge levels for that particular ssh user as indicated in my previous post.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication ssh console LOCAL&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a008069bf1b.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a008069bf1b.shtml&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Jan 2009 01:10:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-read-only-user/m-p/1202020#M877646</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2009-01-20T01:10:42Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Read only User</title>
      <link>https://community.cisco.com/t5/network-security/asa-read-only-user/m-p/1202021#M877648</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;yes I do have the above listed statement and have defined the priviledge level as the first post said.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Jan 2009 20:21:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-read-only-user/m-p/1202021#M877648</guid>
      <dc:creator>angel-moon</dc:creator>
      <dc:date>2009-01-20T20:21:13Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Read only User</title>
      <link>https://community.cisco.com/t5/network-security/asa-read-only-user/m-p/1202022#M877649</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok , you must be missing this statement, try with that user after you enter this in asa  and let me know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;B&gt;aaa authorization command LOCAL&lt;/B&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Additional reference for aaa authorization command &lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/asa/asa80/command/reference/a1.html#wp1537175" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa80/command/reference/a1.html#wp1537175&lt;/A&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Jan 2009 20:46:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-read-only-user/m-p/1202022#M877649</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2009-01-20T20:46:18Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Read only User</title>
      <link>https://community.cisco.com/t5/network-security/asa-read-only-user/m-p/1202023#M877650</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That was it.  Thanks!  Just to make sure, this ASA is also authenticating users for VPN connections by pointing to the domain.  This should not impact those users correct?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks so much!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Jan 2009 20:51:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-read-only-user/m-p/1202023#M877650</guid>
      <dc:creator>angel-moon</dc:creator>
      <dc:date>2009-01-20T20:51:40Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Read only User</title>
      <link>https://community.cisco.com/t5/network-security/asa-read-only-user/m-p/1202024#M877651</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Angel,  it should not impact any VPN related authentication , this only pertains to authorization managing the ASA applience.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Glad it is resolved   and thank you for rating.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Jan 2009 21:49:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-read-only-user/m-p/1202024#M877651</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2009-01-20T21:49:03Z</dc:date>
    </item>
    <item>
      <title>ASA Read only User</title>
      <link>https://community.cisco.com/t5/network-security/asa-read-only-user/m-p/1202025#M877652</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I just stumbled onto this post.&amp;nbsp; I was wondering if there was a generic command to allow access to all show commands, instead of individually having to specify them:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;e.g. at the moment I have a Level 5 user who I want to have access to all show commands, but not configuration mode, and I have to manually specify each command:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;privilege show level 5 mode exec command running-config&lt;/P&gt;&lt;P&gt;privilege show level 5 mode exec command log&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there an equivalent of show * that I can add?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Sep 2012 04:45:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-read-only-user/m-p/1202025#M877652</guid>
      <dc:creator>goulin</dc:creator>
      <dc:date>2012-09-18T04:45:21Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Read only User</title>
      <link>https://community.cisco.com/t5/network-security/asa-read-only-user/m-p/3792163#M877653</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;While it is possible to expose a custom set of commands from ASA CLI for all its contexts as shown below, how do you ensure that the same for system CLI on ASA ? it doesn't seem to be having aaa commands available ?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Enable the use of local command privilege levels, which can be checked against the privilege level of users in the local database&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;asa/Management(config)#&amp;nbsp;&lt;STRONG&gt;aaa authorization command LOCAL&lt;/STRONG&gt;&lt;BR /&gt;asa/Management(config)# exit&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Create a user with privilege level 5 in the local database&amp;nbsp;&lt;/STRONG&gt;&lt;BR /&gt;asa/Management(config)# username &amp;lt;&amp;gt; password &amp;lt;&amp;gt; privilege 5&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;To view privilege levels&lt;/STRONG&gt;&lt;BR /&gt;asa/Management# show curpriv&amp;nbsp;&lt;BR /&gt;Username : &amp;lt;&amp;gt;&lt;BR /&gt;Current privilege level : 5&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Current Mode/s : P_PRIV&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Example:&lt;/P&gt;
&lt;DIV&gt;&lt;SPAN&gt;asa/Management(config)# privilege show level 5 command running-config&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Thu, 31 Jan 2019 13:58:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-read-only-user/m-p/3792163#M877653</guid>
      <dc:creator>akbansal@cisco.com</dc:creator>
      <dc:date>2019-01-31T13:58:05Z</dc:date>
    </item>
  </channel>
</rss>

