cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1166
Views
0
Helpful
1
Replies

How to create read only "sh running-config" user? - IOS device

sossie
Level 1
Level 1

Hi all,

I would like to create a user that is able to logon to an IOS switch and have permissions to show running-config This user is to be used for Cat tools config backup. The user needs to be able to see all config "privledge level 15".

Does anyone have any ideas on how I can achieve this?

A couple of options I have read about but are not suitable for my situation are:

- setup a user that can show startup-config but this is not ideal for security (the running config is the most important)

- setup a user that has level 15 priv and then uses "autocommand show running-config" - but cat tools does not work with this sort of user.

Thanks, Simon.

1 Reply 1

Eduardo Aliaga
Level 4
Level 4

There's an IOS feature called "parser view". But in my opinion the best thing to do is to add an AAA server and configure command authentication between your router and AAA server.