02-03-2006 05:58 AM - edited 02-21-2020 10:14 AM
I cannot seem to restrict a users' access to the monitor tab or to read-only access. I have been told it can be done. Help!
PIX 7.0(2) - ASDM 5.0(2)
02-05-2006 01:40 PM
Hello,
In the ADSM you should find the settings under
Configuration > Features > Device Administration > Administration > AAA Access > Authorization Tab
Authorization lets you control access per user after you authenticate with a valid username and
password. You can configure the security appliance to authorize management commands.
Authorization lets you control which services and commands are available to an individual user.
Authentication alone provides the same access to services for all authenticated users.
When you enable command authorization, you have the option of manually assigning privilege levels to
individual commands or groups of commands (using the Advanced... button) or enabling the Predefined
User Account Privileges (using the Restore Predefined User Account Privileges button).
The Predefined User Account Privileges Setup panel displays a list of commands and privileges ASDM
issues to the security appliance if you click Yes. Yes allows ASDM to support the three privilege levels:
Admin, Read Only and Monitor Only.
The complete explanation can be found in "ASDM Online Help, Release 5.0" at http://www.cisco.com/application/pdf/en/us/guest/products/ps6121/c1225/ccmigration_09186a008045786c.pdf
Hope this helps! Please rate all posts.
Regards, Martin
02-06-2006 04:48 AM
Yes, I can see how this is done if I am doing LOCAL authentication, but if I am authenticating through a AAA server I have to set the authorization on the AAA server and it doesn't seem to work. I am using Cisco ACS TACAS+ server.
02-06-2006 07:13 AM
Oh, sorry I have overlooked your request for ACS.
The description on how to setup command authorization with ACS is found at
In your case the description on how to configure the ACS with examples is at "Configuring Commands on the TACACS+ Server" at
Hope this helps! Please rate all posts.
Regards, Martin
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide