06-23-2008 04:47 AM
Hi all,
Wondering how to implement this:
I have a few techs that need access to the switches to view port configurations.
Although I DO NOT want to give them the enable password.
How can I setup a differente enable password and give them only VIEW (a.k.a. Show) capabilities?
Thanks for your help.
06-23-2008 04:58 AM
Use AAA and assign privilege levels to user accounts.
http://www.cisco.com/en/US/docs/ios/security/configuration/guide/sec_cfg_sec_4cli.html
Hope that helps
06-23-2008 06:06 AM
If the Tech's know what the Enabled password is, is there a way to block them from actualy typing 'enable' ?
06-23-2008 06:08 AM
Yes, well actually they can type it, but they will get an error back.
*There are multiple ways to configure privilege levels and depending on how YOU do it, will depends on the results.
06-23-2008 06:36 AM
ok, can't seem to figure out how to restrict access to the 'enable' ...
I have a username created with privilege level 2, I dont want him to be able to enter enable as he knows the enabled password...
How do I do this?
I only want this user to do show commands... that's it.
06-23-2008 06:41 AM
In AAA you need to configure Authorization. If you want to use local authentication and privilege levels, you have to "move" the commands to level 2 and then change the enable password.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide