cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
471
Views
0
Helpful
3
Replies

Inquiry about Deleting the Admin Account on Nexus 3548-XL

sonts12
Level 1
Level 1

Hello,

I’m using a Nexus 3548-XL running NX-OS 10.3(6). Due to a recent security issue, I’m trying to delete the default admin account.

I have already created a new account with the network-admin role, but when I attempt to remove the existing admin account, I get the following message and the deletion fails:
“admin account can not be deactivated”

I checked the official documentation and found language for the Nexus 9000 Series stating that the default admin and SNMP user accounts cannot be deleted:
Cisco Nexus 9000 Series NX-OS Security Configuration Guide, Release 10.3(x) > Guidelines and Limitations for User Accounts and RBAC — “You cannot delete the default admin and SNMP user accounts.”

However, I could not find the same statement in the 3548 documentation:
Cisco Nexus 3548 Switch NX-OS System Management Configuration Guide, Release 10.3(x) > Guidelines and Limitations for User Accounts

On a Nexus 3548-XL with NX-OS 10.3(6), is it not possible to delete the admin account?
If deletion is not supported, could you please point me to any official statement or documentation that explicitly confirms this restriction?

Thank you.

1 Accepted Solution

Accepted Solutions

Enes Simnica
Spotlight
Spotlight

hello @sonts12 That is correct, cause even though the Nexus 3548 documentation doesn’t explicitly say it, the default admin account on NX-OS 10.3(6) also cannot be deleted or deactivated. This restriction is built into NX-os itself, not just the Nx 9000 series. That’s why you’re getting the “admin account can not be deactivated” error.

Unfortunately, Cisco doesn’t have a separate statement for the 3548 platform (or i haven't seen that yet!!))), but the behavior is consistent across all NX-OS-based devices. And if u ask me, u can safely assume the same limitation applies.

hope it helps!

 

-Enes

more Cisco?!
more Gym?!



If this post solved your problem, kindly mark it as Accepted Solution. Much appreciated!

View solution in original post

3 Replies 3

Enes Simnica
Spotlight
Spotlight

hello @sonts12 That is correct, cause even though the Nexus 3548 documentation doesn’t explicitly say it, the default admin account on NX-OS 10.3(6) also cannot be deleted or deactivated. This restriction is built into NX-os itself, not just the Nx 9000 series. That’s why you’re getting the “admin account can not be deactivated” error.

Unfortunately, Cisco doesn’t have a separate statement for the 3548 platform (or i haven't seen that yet!!))), but the behavior is consistent across all NX-OS-based devices. And if u ask me, u can safely assume the same limitation applies.

hope it helps!

 

-Enes

more Cisco?!
more Gym?!



If this post solved your problem, kindly mark it as Accepted Solution. Much appreciated!

balaji.bandi
Hall of Fame
Hall of Fame

I think this still valid for all nexus switches :

Guidelines and Limitations for User Accounts and RBAC

  • You cannot delete the default admin and SNMP user accounts.

https://www.cisco.com/c/en/us/td/docs/switches/datacenter/nexus9000/sw/6-x/security/configuration/guide/b_Cisco_Nexus_9000_Series_NX-OS_Security_Configuration_Guide/b_Cisco_Nexus_9000_Series_NX-OS_Security_Configuration_Guide_chapter_01001.html

BB

=====Preenayamo Vasudevam=====

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

M02@rt37
VIP
VIP

Hello @sonts12 

For that Nexus model nothing clear or explicit about admin account deletion.

Regarding the error message we could think of Nexus9k behavior...

If we want clear explanation, you should open Cisco TAC case.

 

Best regards
.ı|ı.ı|ı. If This Helps, Please Rate .ı|ı.ı|ı.