cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1028
Views
0
Helpful
3
Replies

basic question about privilege level

sundayviet
Community Member

 I know there are 16 privilege levels of cisco router/switch manage account (from 0-15). Anyone tell me detail what difference of these level are ? or any document about this ? Thank all!

2 Accepted Solutions

Accepted Solutions

Philip D'Ath
Meraki Community All-Star
Meraki Community All-Star

Basically 0,1 and 15 are the only ones used by default.

There are five commands associated with privilege level 0: disable, enable, exit, help, and logout

Level 1 is what you get when you logged in without any special privileges.

Level 2 through 14 give you the same as level 1 by default.

Level 15 is "all access".

Levels 2 through 14 are more intended to be defined by the system administrator as to what is permitted.

You can used role based access control.

http://www.cisco.com/en/US/docs/ios/12_3t/12_3t7/feature/guide/gtclivws.html

Instead of role based access control you assign users to specific privilege levels, and the commands they are allowed to run.

http://www.cisco.com/c/en/us/support/docs/security-vpn/terminal-access-controller-access-control-system-tacacs-/23383-showrun.html

View solution in original post

Philip D'Ath
Meraki Community All-Star
Meraki Community All-Star

You couldn't mark my answer as correct and give it a rating could you please ...

View solution in original post

3 Replies 3

Philip D'Ath
Meraki Community All-Star
Meraki Community All-Star

Basically 0,1 and 15 are the only ones used by default.

There are five commands associated with privilege level 0: disable, enable, exit, help, and logout

Level 1 is what you get when you logged in without any special privileges.

Level 2 through 14 give you the same as level 1 by default.

Level 15 is "all access".

Levels 2 through 14 are more intended to be defined by the system administrator as to what is permitted.

You can used role based access control.

http://www.cisco.com/en/US/docs/ios/12_3t/12_3t7/feature/guide/gtclivws.html

Instead of role based access control you assign users to specific privilege levels, and the commands they are allowed to run.

http://www.cisco.com/c/en/us/support/docs/security-vpn/terminal-access-controller-access-control-system-tacacs-/23383-showrun.html

I know clearly, thank so much, dath! I'm implementing RBAC!

Philip D'Ath
Meraki Community All-Star
Meraki Community All-Star

You couldn't mark my answer as correct and give it a rating could you please ...