cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
746
Views
0
Helpful
3
Replies

users privilege in Cisco Router and ASA

mohamed.ali
Level 1
Level 1

Dears,

 

please, I have junior network engineers I wanna to create to them read-only users in Cisco Router and ASA.
I wanna the standard command that I'll link it with users privilege.

like:

 

username blabla privilege 10  secret blabla

 

 

thanks,

3 Replies 3

For an easy read-only-access, just make sure that they get a user-mode-login, but don't provide the enable-password. The privilege-levels are only needed if your junior-admins also need commands that are only available in level 15.

The best way to control all this is from your TACACS-server.

there are other choices?

as well for ASA ?

For sure there are many choices:

  1. As mentioned, the most flexible and powerful ist the use of TACACS+. There is also a free server available: http://tacacs.net/download.asp
  2. The privilege-levels are available on all platforms but need to be configured on all devices in a similar fashion. If you don't have a central configuration-management, this could become quite difficult.
  3. On IOS, there is also RBAC. But that is not available on ASAs.