cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1417
Views
0
Helpful
2
Replies

Controling privilege levels on PIX with Radius

ronald_beaulieu
Level 1
Level 1

We have a PIX 515 and we are trying to control privilege levels when our admins login to the console port or Telnet. we have the following config

aaa-server RADIUS (inside) host 192.168.x.x MySecretKey timeout 4

aaa authentication telnet console RADIUS

aaa authentication enable console RADIUS

aaa authentication serial console RADIUS

This allows us to have the Radius authenticate the access but once you have access you can go to Enable mode and all it does is prompt you for your Uid/pswd again.

My Radius server supports the Cisco AV Pairs so i tried adding in the users profil the attributes shell:priv-lvl=15 for admins.

I also tried adding the atribute Service-type=Login and Service-type=Administrative it still doesn't control the Enable mode access.

Any help or guidance would be appreciated.

Ronald.

2 Replies 2

jekrauss
Level 1
Level 1

Unlike the IOS on a router, there is no authorization or command authorization on the pix.

HTH

Jeff

Let me add just a clarifying comment. You can, of course, perform authorization THROUGH the PIX, just not authorization of users administering the pix - just authentication.

Review Cisco Networking for a $25 gift card