<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CLI based Roles/Views in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cli-based-roles-views/m-p/1506271#M923005</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This issue persists. Is anyone able to offer some insight/suggestion on my problem?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TIA&lt;/P&gt;&lt;P&gt;Rgds&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 20 Sep 2010 05:20:28 GMT</pubDate>
    <dc:creator>Scott Cannon</dc:creator>
    <dc:date>2010-09-20T05:20:28Z</dc:date>
    <item>
      <title>CLI based Roles/Views</title>
      <link>https://community.cisco.com/t5/network-security/cli-based-roles-views/m-p/1506268#M923002</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm trying to configure a view that will allow a user access to do a few mundane tasks such as read the startup conifg, a few show commands, change the terminal settings, etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've configure a view called RO and assigned a few exec commands (see below):&lt;/P&gt;&lt;P&gt;&lt;EM&gt;parser view RO&lt;BR /&gt; secret 5 $1$m3Iz$ltDKR58NxImIZEEwX/vbV0&lt;BR /&gt; commands exec include terminal length&lt;BR /&gt; commands exec include terminal&lt;BR /&gt; commands exec include show startup-config&lt;BR /&gt; commands exec include show&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;I've also created a user and assigned it to this view&lt;/P&gt;&lt;P&gt;&lt;EM&gt;username sc view RO password 0 sc&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now, when I login with the user &lt;EM&gt;sc&lt;/EM&gt; I am unable to move from user mode to privliged mode, I get an access denied error as seen below:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;R1&amp;gt;en&lt;BR /&gt;Password:&lt;BR /&gt;% Access denied&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have I done something wrong? How do I configure the router so that I can create a role with the required commands and assign it to users? I thought I had it down pat but it isnt working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any advice you have would be greatly appreciated&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TIA&lt;/P&gt;&lt;P&gt;Rgds&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 12:04:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cli-based-roles-views/m-p/1506268#M923002</guid>
      <dc:creator>Scott Cannon</dc:creator>
      <dc:date>2020-02-21T12:04:48Z</dc:date>
    </item>
    <item>
      <title>Re: CLI based Roles/Views</title>
      <link>https://community.cisco.com/t5/network-security/cli-based-roles-views/m-p/1506269#M923003</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Scott,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your user probably does have priv level to be in enable mode. &lt;/P&gt;&lt;P&gt;IF he is in priv 15, does it work?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Sep 2010 14:40:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cli-based-roles-views/m-p/1506269#M923003</guid>
      <dc:creator>Panos Kampanakis</dc:creator>
      <dc:date>2010-09-10T14:40:33Z</dc:date>
    </item>
    <item>
      <title>Re: CLI based Roles/Views</title>
      <link>https://community.cisco.com/t5/network-security/cli-based-roles-views/m-p/1506270#M923004</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi PK,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your input.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I give the account privilege 15 it works but then the view does not (ie. the account can run all commands). I suspect this is how it should be since priv15 is akin to god-mode access and you shouldnt be able to restrict it. Also means, giving privilege 15 isnt a solution. I've scoured the web with no luck.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can any one offer further insight into my issue?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TIA&lt;/P&gt;&lt;P&gt;Rgds&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Sep 2010 22:34:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cli-based-roles-views/m-p/1506270#M923004</guid>
      <dc:creator>Scott Cannon</dc:creator>
      <dc:date>2010-09-13T22:34:44Z</dc:date>
    </item>
    <item>
      <title>Re: CLI based Roles/Views</title>
      <link>https://community.cisco.com/t5/network-security/cli-based-roles-views/m-p/1506271#M923005</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This issue persists. Is anyone able to offer some insight/suggestion on my problem?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TIA&lt;/P&gt;&lt;P&gt;Rgds&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Sep 2010 05:20:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cli-based-roles-views/m-p/1506271#M923005</guid>
      <dc:creator>Scott Cannon</dc:creator>
      <dc:date>2010-09-20T05:20:28Z</dc:date>
    </item>
    <item>
      <title>Re: CLI based Roles/Views</title>
      <link>https://community.cisco.com/t5/network-security/cli-based-roles-views/m-p/1506272#M923006</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The "Access denied" error comes from aaa authentication, and in theory shouldn't have much to do with role based view access. Does this work if you don't assign the RO view to this user "sc"? Also, if you assign both a parser view and the privilege level to an user, the parser view should take precedence, ie., the users should still only be able to see commands assigned to the view, and not all commands under level 15. To better understand what's going on, could you post your aaa configuration, along with a "debug aaa authen" when it's not working?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Wen&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Oct 2010 16:45:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cli-based-roles-views/m-p/1506272#M923006</guid>
      <dc:creator>wzhang</dc:creator>
      <dc:date>2010-10-08T16:45:13Z</dc:date>
    </item>
    <item>
      <title>Re: CLI based Roles/Views</title>
      <link>https://community.cisco.com/t5/network-security/cli-based-roles-views/m-p/1506273#M923007</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi wzhang,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for coming back to me on this. The fix for this problem still eludes me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I dont assign the RO view to the user and enable it fails authentication (wrong passowrd) If I then manually tell the user to enable (into) the RO view then it works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I assign priviledge level 15 to the line the user is automatically logged into exec mode and has access to all commands, regardless of what view is assigned to the user.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think whats happening is this:&lt;/P&gt;&lt;P&gt;When the view is assigned to the user SC, I login as SC and type enable at the user prompt. Instead of enabling the view assigned to the user (in this case RO) it enables the root view and as such fails authentication. If I manually enable the RO view via &lt;EM&gt;enable view RO&lt;/EM&gt; it works as expected.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I suppose my question now is: How do I change this behaviour so that when a user with a view assigned o them types enable, it moves them into the view assigned to them (and not the root view)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TIA&lt;/P&gt;&lt;P&gt;Rgds&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Oct 2010 04:44:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cli-based-roles-views/m-p/1506273#M923007</guid>
      <dc:creator>Scott Cannon</dc:creator>
      <dc:date>2010-10-19T04:44:53Z</dc:date>
    </item>
    <item>
      <title>Re: CLI based Roles/Views</title>
      <link>https://community.cisco.com/t5/network-security/cli-based-roles-views/m-p/1506274#M923008</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, Scott:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you share your aaa configuration? A couple of things to note here:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. With aaa authorization enabled, when an user logs into the router he should automatically be assigned the view that the user belongs to. You shouldn't have to enable into the view manually.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. When the user is in the view he/she's assigned to and he/she types "enable", then he will be put into the privileged mode, and not the root view as in the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;R1#telnet 1.1.1.1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;Trying 1.1.1.1 ... Open&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;User Access Verification&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;Username: cisco&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;Password: &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;R2#sh parser view&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;Current view is 'MYVIEW'&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;R2#&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;R2#enable&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;Password: &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;R2#&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;R2#sh parser view&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;No view is active ! Currently in Privilege Level Context&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;R2#&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;3. You typically don't want to assign privilege levels to the line, but instead you want to do it for the user either through AAA or assign it locally, although with role based CLI access, it's somewhat of a moot point since the commands the user has access to is controlled by the view and not the privilege level.&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;Thanks,&lt;/DIV&gt;&lt;DIV&gt;Wen&lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Oct 2010 14:06:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cli-based-roles-views/m-p/1506274#M923008</guid>
      <dc:creator>wzhang</dc:creator>
      <dc:date>2010-10-19T14:06:06Z</dc:date>
    </item>
    <item>
      <title>Re: CLI based Roles/Views</title>
      <link>https://community.cisco.com/t5/network-security/cli-based-roles-views/m-p/1506275#M923009</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Wen,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;See config extract below:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;VIEWS_R1#sho run&lt;BR /&gt;Building configuration...&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Current configuration : 1218 bytes&lt;BR /&gt;!&lt;BR /&gt;version 12.4&lt;BR /&gt;service timestamps debug datetime msec&lt;BR /&gt;service timestamps log datetime msec&lt;BR /&gt;no service password-encryption&lt;BR /&gt;!&lt;BR /&gt;hostname VIEWS_R1&lt;BR /&gt;!&lt;BR /&gt;boot-start-marker&lt;BR /&gt;boot-end-marker&lt;BR /&gt;!&lt;BR /&gt;enable password password&lt;BR /&gt;!&lt;BR /&gt;aaa new-model&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;aaa authentication login default local&lt;BR /&gt;aaa authorization exec default if-authenticated&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;no ip domain lookup&lt;BR /&gt;ip auth-proxy max-nodata-conns 3&lt;BR /&gt;ip admission max-nodata-conns 3&lt;BR /&gt;!&lt;BR /&gt;username sc privilege 15 password 0 abc123&lt;BR /&gt;username sc2 view RO password 0 abc123&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/0&lt;BR /&gt; ip address 10.0.0.1 255.0.0.0&lt;BR /&gt; duplex auto&lt;BR /&gt; speed auto&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;line con 0&lt;BR /&gt; logging synchronous&lt;BR /&gt;line aux 0&lt;BR /&gt;line vty 0 4&lt;BR /&gt; transport input telnet&lt;BR /&gt;line vty 5 14&lt;BR /&gt; transport input telnet&lt;BR /&gt;line vty 15&lt;BR /&gt; transport input telnet&lt;BR /&gt;parser view RO&lt;BR /&gt; secret 5 $1$E6ex$JrkjcJd94q4vM/QrQL9F31&lt;BR /&gt; commands exec include terminal length&lt;BR /&gt; commands exec include terminal&lt;BR /&gt; commands exec include show startup-config&lt;BR /&gt; commands exec include show&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;end&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note: This config differs slightly from that mentioned in my previous posts. I've had to rebuild it as I lost my test environment. In the above config, the user sc2 is assigned the view RO. I'm doing all this testing in GNS3, happy to upload the configs for you if you prefer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A difference I have noticed between your output and what I get is that my user "sc2" is not logged into privilged mode. I guess this is because I dont have it set on the vty lines. If I do set it, as already stated, the view doesnt take affect and the user gets all commands available to that priv level.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Heres what I see (I've added the passwords so you can see waht I'm doing):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;User Access Verification&lt;/P&gt;&lt;P&gt;Username: sc2 &lt;STRONG&gt;(this user has the RO view assigned to them)&lt;/STRONG&gt;&lt;BR /&gt;Password: abc123&lt;/P&gt;&lt;P&gt;VIEWS_R1&amp;gt;en&lt;BR /&gt;Password: RO &lt;STRONG&gt;(the RO view enable password)&lt;/STRONG&gt;&lt;BR /&gt;% Access denied&lt;/P&gt;&lt;P&gt;VIEWS_R1&amp;gt;en&lt;BR /&gt;Password: password &lt;STRONG&gt;(the root view enable password)&lt;/STRONG&gt;&lt;BR /&gt;VIEWS_R1#sho parser view&lt;BR /&gt;No view is active ! Currently in Privilege Level Context&lt;BR /&gt;VIEWS_R1#sho run | i sc2&lt;BR /&gt;username sc2 view RO password 0 abc123&lt;BR /&gt;VIEWS_R1#&lt;/P&gt;&lt;P&gt;Any idea why my view isnt taking affect?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgds&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Oct 2010 04:14:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cli-based-roles-views/m-p/1506275#M923009</guid>
      <dc:creator>Scott Cannon</dc:creator>
      <dc:date>2010-10-20T04:14:49Z</dc:date>
    </item>
    <item>
      <title>Re: CLI based Roles/Views</title>
      <link>https://community.cisco.com/t5/network-security/cli-based-roles-views/m-p/1506276#M923010</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, Scott:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think the problem is that your aaa authorization is not taking effect, thus not putting the user into the parser view assigned to him. With your authorization configuration, if-authenticated means don't authorize if the user is authenticated already. Try changing that to "aaa authorization exec default local" and that _should_ fix it. The reason that my user goes into the privileged mode right away is because I've assigned privilege 15 to the user. But then again, with role based cli access, the parser view should take precedence over the privilege level, so it's somewhat of a moot point. Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Wen&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Oct 2010 13:34:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cli-based-roles-views/m-p/1506276#M923010</guid>
      <dc:creator>wzhang</dc:creator>
      <dc:date>2010-10-20T13:34:18Z</dc:date>
    </item>
    <item>
      <title>CLI based Roles/Views</title>
      <link>https://community.cisco.com/t5/network-security/cli-based-roles-views/m-p/1506277#M923011</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I know this is an old post but I came across the same issue. The way I resolved it is to not have the user do an enable after inputting their credentials. At user mode they need to type:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;R1&amp;gt; enable view RO&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Password: RO-password&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;R1#&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;*Oct 11 05:54:26.523: %PARSER-6-VIEW_SWITCH: successfully set to view 'RO'.&lt;/EM&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Oct 2012 12:55:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cli-based-roles-views/m-p/1506277#M923011</guid>
      <dc:creator>Rowell Dionicio</dc:creator>
      <dc:date>2012-10-11T12:55:21Z</dc:date>
    </item>
    <item>
      <title>Re: CLI based Roles/Views</title>
      <link>https://community.cisco.com/t5/network-security/cli-based-roles-views/m-p/5007313#M1108532</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;&lt;BR /&gt;Please do note that the client or user on which view has to be applied will &lt;STRONG&gt;NOT be using the enable command&lt;/STRONG&gt;. Doing so will enable priviledge levels.&lt;BR /&gt;Strangely enough, the client / user on whom view is applied will &lt;STRONG&gt;enter the view assigned commands directly in the default mode(user exec)&lt;/STRONG&gt; that the user logs in.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;#RoleBasedAccessControl #RBAC&lt;/P&gt;</description>
      <pubDate>Sun, 28 Jan 2024 10:20:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cli-based-roles-views/m-p/5007313#M1108532</guid>
      <dc:creator>SohelJapanwala</dc:creator>
      <dc:date>2024-01-28T10:20:07Z</dc:date>
    </item>
  </channel>
</rss>

